I was on this website for my research and all of a sudden I started getting fake alerts to buy security protection products. Unfortuately the first time it popped up, I didn't realize this is a spyware/malware and I clicked "remove all" thinking I was removing these issues. I then ran SuperAntiSpyware to try to get rid off all the pop up screens. Their scan showed that they found Trojan.Agent/Gen-FakeAlert and BrowserHijakcer.Internet Explorer Settings Hijack. SuperAntiSpyware seemed to get rid of the popup windows but I want to make sure that my registry is clean and everything else is removed as well. How do I proceed?
In the past, Broni walked me through all the steps for another issue and was really helpful to me. I hope to get rid off everything with your help this time. Thank you!
Welcome aboard
Please, complete all steps listed here: HERE
Please, observe following rules:
- Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
- If you're stuck, or you're not sure about certain step, always ask before doing anything else.
- Please refrain from running tools or applying updates other than those I suggest.
- Never run more than one scan at a time.
- Keep updating me regarding your computer behavior, good, or bad.
- The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
- If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
- I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
Broni,
Thank you for your reply. I downloaded Avira, which displayed this message when I restarted my computer "the access to autorun.inf" was blocked.
Since I downloaded Malware last time, I updated it instead of redownloading the whole thing. I ran the .exe file you mentioned. It asked me to restart the computer so I did. But I didn't see the part where it asked me to "checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware," but I did see the application file to run from last time. So although it did not launch automatically after I ran the .exe file, I clicked on that icon and saw the screen you were referring to to perform the quick scan. Is this ok? Or should I go ahead and delete the old Malware and then reinstall it like it was the first time. Anyway, if what I did was okay, here is the log results:
From Malware:
Malwarebytes' Anti-Malware 1.51.0.1200
Malwarebytes : Free anti-malware, anti-virus and spyware removal download
Database version: 6705
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19048
6/4/2011 12:07:52 PM
mbam-log-2011-06-04 (12-07-52).txt
Scan type: Quick scan
Objects scanned: 170905
Time elapsed: 8 minute(s), 26 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 1
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CLASSES_ROOT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://findgala.com/?&uid=2194&q={searchTerms}) Good: (http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language }&ie={inputEncoding}&oe={outputEncoding}&startInde x={startIndex?}&startPage={startPage}) -> Quarantined and deleted successfully.
Folders Infected:
c:\Users\lqi\AppData\Roaming\pc security guardian (Rogue.PCSecurityGuardian) -> Quarantined and deleted successfully.
Files Infected:
c:\Users\lqi\AppData\Roaming\pc security guardian\instructions.ini (Rogue.PCSecurityGuardian) -> Quarantined and deleted successfully.
c:\Users\lqi\AppData\Roaming\pc security guardian\cookies.sqlite (Rogue.PCSecurityGuardian) -> Quarantined and deleted successfully.
From gmer:
GMER 1.0.15.15640 - GMER - Rootkit Detector and Remover
Rootkit scan 2011-06-04 13:42:39
Windows 6.0.6002 Service Pack 2
Running: 20zu1ehy.exe
---- Files - GMER 1.0.15 ----
File C:\RRbackups\C 0 bytes
File C:\RRbackups\C\0 0 bytes
File C:\RRbackups\C\0\Data479 50003968 bytes
File C:\RRbackups\C\0\Data0 50003968 bytes
File C:\RRbackups\C\0\Data1 50003968 bytes
File C:\RRbackups\C\0\Data10 50003968 bytes
File C:\RRbackups\C\0\Data100 50003968 bytes
File C:\RRbackups\C\0\Data1000 50003968 bytes
File C:\RRbackups\C\0\Data1001 50003968 bytes
File C:\RRbackups\C\0\Data1002 50003968 bytes
File C:\RRbackups\C\0\Data1003 50003968 bytes
File C:\RRbackups\C\0\Data1004 50003968 bytes
File C:\RRbackups\C\0\Data1005 50003968 bytes
File C:\RRbackups\C\0\Data1006 50003968 bytes
File C:\RRbackups\C\0\Data1007 50003968 bytes
File C:\RRbackups\C\0\Data1008 50003968 bytes
File C:\RRbackups\C\0\Data1009 50003968 bytes
File C:\RRbackups\C\0\Data101 50003968 bytes
File C:\RRbackups\C\0\Data1010 50003968 bytes
File C:\RRbackups\C\0\Data1011 50003968 bytes
File C:\RRbackups\C\0\Data1012 50003968 bytes
File C:\RRbackups\C\0\Data1013 50003968 bytes
File C:\RRbackups\C\0\Data1014 50003968 bytes
File C:\RRbackups\C\0\Data1015 50003968 bytes
File C:\RRbackups\C\0\Data1016 47697952 bytes
File C:\RRbackups\C\0\Data102 50003968 bytes
File C:\RRbackups\C\0\Data103 50003968 bytes
File C:\RRbackups\C\0\Data104 50003968 bytes
File C:\RRbackups\C\0\Data105 50003968 bytes
File C:\RRbackups\C\0\Data106 50003968 bytes
File C:\RRbackups\C\0\Data107 50003968 bytes
File C:\RRbackups\C\0\Data108 50003968 bytes
File C:\RRbackups\C\0\Data109 50003968 bytes
File C:\RRbackups\C\0\Data11 50003968 bytes
File C:\RRbackups\C\0\Data110 50003968 bytes
File C:\RRbackups\C\0\Data111 50003968 bytes
File C:\RRbackups\C\0\Data112 50003968 bytes
File C:\RRbackups\C\0\Data113 50003968 bytes
File C:\RRbackups\C\0\Data114 50003968 bytes
File C:\RRbackups\C\0\Data115 50003968 bytes
File C:\RRbackups\C\0\Data270 50003968 bytes
File C:\RRbackups\C\0\Data271 50003968 bytes
File C:\RRbackups\C\0\Data272 50003968 bytes
File C:\RRbackups\C\0\Data273 50003968 bytes
File C:\RRbackups\C\0\Data274 50003968 bytes
File C:\RRbackups\C\0\Data275 50003968 bytes
File C:\RRbackups\C\0\Data276 50003968 bytes
File C:\RRbackups\C\0\Data277 50003968 bytes
File C:\RRbackups\C\0\Data278 50003968 bytes
File C:\RRbackups\C\0\Data279 50003968 bytes
File C:\RRbackups\C\0\Data28 50003968 bytes
File C:\RRbackups\C\0\Data280 50003968 bytes
File C:\RRbackups\C\0\Data281 50003968 bytes
File C:\RRbackups\C\0\Data282 50003968 bytes
File C:\RRbackups\C\0\Data283 50003968 bytes
File C:\RRbackups\C\0\Data284 50003968 bytes
File C:\RRbackups\C\0\Data285 50003968 bytes
File C:\RRbackups\C\0\Data286 50003968 bytes
File C:\RRbackups\C\0\Data287 50003968 bytes
File C:\RRbackups\C\0\Data288 50003968 bytes
File C:\RRbackups\C\0\Data460 50003968 bytes
File C:\RRbackups\C\0\Data461 50003968 bytes
File C:\RRbackups\C\0\Data462 50003968 bytes
File C:\RRbackups\C\0\Data463 50003968 bytes
File C:\RRbackups\C\0\Data464 50003968 bytes
File C:\RRbackups\C\0\Data465 50003968 bytes
File C:\RRbackups\C\0\Data466 50003968 bytes
File C:\RRbackups\C\0\Data467 50003968 bytes
File C:\RRbackups\C\0\Data468 50003968 bytes
File C:\RRbackups\C\0\Data469 50003968 bytes
File C:\RRbackups\C\0\Data47 50003968 bytes
File C:\RRbackups\C\0\Data470 50003968 bytes
File C:\RRbackups\C\0\Data471 50003968 bytes
File C:\RRbackups\C\0\Data472 50003968 bytes
File C:\RRbackups\C\0\Data473 50003968 bytes
File C:\RRbackups\C\0\Data474 50003968 bytes
File C:\RRbackups\C\0\Data475 50003968 bytes
File C:\RRbackups\C\0\Data476 50003968 bytes
File C:\RRbackups\C\0\Data477 50003968 bytes
File C:\RRbackups\C\0\Data478 50003968 bytes
File C:\RRbackups\C\0\Data650 50003968 bytes
File C:\RRbackups\C\0\Data651 50003968 bytes
File C:\RRbackups\C\0\Data652 50003968 bytes
File C:\RRbackups\C\0\Data653 50003968 bytes
File C:\RRbackups\C\0\Data654 50003968 bytes
File C:\RRbackups\C\0\Data655 50003968 bytes
File C:\RRbackups\C\0\Data656 50003968 bytes
File C:\RRbackups\C\0\Data657 50003968 bytes
File C:\RRbackups\C\0\Data658 50003968 bytes
File C:\RRbackups\C\0\Data659 50003968 bytes
File C:\RRbackups\C\0\Data66 50003968 bytes
File C:\RRbackups\C\0\Data660 50003968 bytes
File C:\RRbackups\C\0\Data661 50003968 bytes
File C:\RRbackups\C\0\Data662 50003968 bytes
File C:\RRbackups\C\0\Data663 50003968 bytes
File C:\RRbackups\C\0\Data664 50003968 bytes
File C:\RRbackups\C\0\Data665 50003968 bytes
File C:\RRbackups\C\0\Data666 50003968 bytes
File C:\RRbackups\C\0\Data667 50003968 bytes
File C:\RRbackups\C\0\Data668 50003968 bytes
File C:\RRbackups\C\0\Data117 50003968 bytes
File C:\RRbackups\C\0\Data118 50003968 bytes
File C:\RRbackups\C\0\Data119 50003968 bytes
File C:\RRbackups\C\0\Data12 50003968 bytes
File C:\RRbackups\C\0\Data120 50003968 bytes
File C:\RRbackups\C\0\Data121 50003968 bytes
File C:\RRbackups\C\0\Data122 50003968 bytes
File C:\RRbackups\C\0\Data123 50003968 bytes
File C:\RRbackups\C\0\Data124 50003968 bytes
File C:\RRbackups\C\0\Data125 50003968 bytes
File C:\RRbackups\C\0\Data126 50003968 bytes
File C:\RRbackups\C\0\Data127 50003968 bytes
File C:\RRbackups\C\0\Data128 50003968 bytes
File C:\RRbackups\C\0\Data129 50003968 bytes
File C:\RRbackups\C\0\Data13 50003968 bytes
File C:\RRbackups\C\0\Data130 50003968 bytes
File C:\RRbackups\C\0\Data131 50003968 bytes
File C:\RRbackups\C\0\Data132 50003968 bytes
File C:\RRbackups\C\0\Data133 50003968 bytes
File C:\RRbackups\C\0\Data134 50003968 bytes
File C:\RRbackups\C\0\Data136 50003968 bytes
File C:\RRbackups\C\0\Data137 50003968 bytes
File C:\RRbackups\C\0\Data138 50003968 bytes
File C:\RRbackups\C\0\Data139 50003968 bytes
File C:\RRbackups\C\0\Data14 50003968 bytes
File C:\RRbackups\C\0\Data140 50003968 bytes
File C:\RRbackups\C\0\Data141 50003968 bytes
File C:\RRbackups\C\0\Data142 50003968 bytes
File C:\RRbackups\C\0\Data143 50003968 bytes
File C:\RRbackups\C\0\Data144 50003968 bytes
File C:\RRbackups\C\0\Data145 50003968 bytes
File C:\RRbackups\C\0\Data146 50003968 bytes
File C:\RRbackups\C\0\Data147 50003968 bytes
File C:\RRbackups\C\0\Data148 50003968 bytes
File C:\RRbackups\C\0\Data149 50003968 bytes
File C:\RRbackups\C\0\Data15 50003968 bytes
File C:\RRbackups\C\0\Data150 50003968 bytes
File C:\RRbackups\C\0\Data151 50003968 bytes
File C:\RRbackups\C\0\Data152 50003968 bytes
File C:\RRbackups\C\0\Data153 50003968 bytes
File C:\RRbackups\C\0\Data155 50003968 bytes
File C:\RRbackups\C\0\Data156 50003968 bytes
File C:\RRbackups\C\0\Data157 50003968 bytes
File C:\RRbackups\C\0\Data158 50003968 bytes
File C:\RRbackups\C\0\Data159 50003968 bytes
File C:\RRbackups\C\0\Data16 50003968 bytes
File C:\RRbackups\C\0\Data160 50003968 bytes
File C:\RRbackups\C\0\Data161 50003968 bytes
File C:\RRbackups\C\0\Data162 50003968 bytes
File C:\RRbackups\C\0\Data163 50003968 bytes
File C:\RRbackups\C\0\Data164 50003968 bytes
File C:\RRbackups\C\0\Data165 50003968 bytes
File C:\RRbackups\C\0\Data166 50003968 bytes
File C:\RRbackups\C\0\Data167 50003968 bytes
File C:\RRbackups\C\0\Data168 50003968 bytes
File C:\RRbackups\C\0\Data169 50003968 bytes
File C:\RRbackups\C\0\Data17 50003968 bytes
File C:\RRbackups\C\0\Data170 50003968 bytes
File C:\RRbackups\C\0\Data171 50003968 bytes
File C:\RRbackups\C\0\Data172 50003968 bytes
File C:\RRbackups\C\0\Data116 50003968 bytes
File C:\RRbackups\C\0\Data135 50003968 bytes
File C:\RRbackups\C\0\Data154 50003968 bytes
File C:\RRbackups\C\0\Data173 50003968 bytes
File C:\RRbackups\C\0\Data192 50003968 bytes
File C:\RRbackups\C\0\Data210 50003968 bytes
File C:\RRbackups\C\0\Data23 50003968 bytes
File C:\RRbackups\C\0\Data249 50003968 bytes
File C:\RRbackups\C\0\Data27 50003968 bytes
File C:\RRbackups\C\0\Data289 50003968 bytes
File C:\RRbackups\C\0\Data307 50003968 bytes
File C:\RRbackups\C\0\Data326 50003968 bytes
File C:\RRbackups\C\0\Data345 50003968 bytes
File C:\RRbackups\C\0\Data364 50003968 bytes
File C:\RRbackups\C\0\Data383 50003968 bytes
File C:\RRbackups\C\0\Data401 50003968 bytes
File C:\RRbackups\C\0\Data420 50003968 bytes
File C:\RRbackups\C\0\Data44 50003968 bytes
File C:\RRbackups\C\0\Data46 50003968 bytes
File C:\RRbackups\C\0\Data174 50003968 bytes
File C:\RRbackups\C\0\Data175 50003968 bytes
File C:\RRbackups\C\0\Data176 50003968 bytes
File C:\RRbackups\C\0\Data177 50003968 bytes
File C:\RRbackups\C\0\Data178 50003968 bytes
File C:\RRbackups\C\0\Data179 50003968 bytes
File C:\RRbackups\C\0\Data18 50003968 bytes
File C:\RRbackups\C\0\Data180 50003968 bytes
File C:\RRbackups\C\0\Data181 50003968 bytes
File C:\RRbackups\C\0\Data182 50003968 bytes
File C:\RRbackups\C\0\Data183 50003968 bytes
File C:\RRbackups\C\0\Data184 50003968 bytes
File C:\RRbackups\C\0\Data185 50003968 bytes
File C:\RRbackups\C\0\Data186 50003968 bytes
File C:\RRbackups\C\0\Data187 50003968 bytes
File C:\RRbackups\C\0\Data188 50003968 bytes
File C:\RRbackups\C\0\Data189 50003968 bytes
File C:\RRbackups\C\0\Data19 50003968 bytes
File C:\RRbackups\C\0\Data190 50003968 bytes
File C:\RRbackups\C\0\Data191 50003968 bytes
File C:\RRbackups\C\0\Data193 50003968 bytes
File C:\RRbackups\C\0\Data194 50003968 bytes
File C:\RRbackups\C\0\Data195 50003968 bytes
File C:\RRbackups\C\0\Data196 50003968 bytes
File C:\RRbackups\C\0\Data197 50003968 bytes
File C:\RRbackups\C\0\Data198 50003968 bytes
File C:\RRbackups\C\0\Data199 50003968 bytes
File C:\RRbackups\C\0\Data2 50003968 bytes
File C:\RRbackups\C\0\Data20 50003968 bytes
File C:\RRbackups\C\0\Data200 50003968 bytes
File C:\RRbackups\C\0\Data201 50003968 bytes
File C:\RRbackups\C\0\Data202 50003968 bytes
File C:\RRbackups\C\0\Data203 50003968 bytes
File C:\RRbackups\C\0\Data204 50003968 bytes
File C:\RRbackups\C\0\Data205 50003968 bytes
File C:\RRbackups\C\0\Data206 50003968 bytes
File C:\RRbackups\C\0\Data207 50003968 bytes
File C:\RRbackups\C\0\Data208 50003968 bytes
File C:\RRbackups\C\0\Data209 50003968 bytes
File C:\RRbackups\C\0\Data21 50003968 bytes
File C:\RRbackups\C\0\Data211 50003968 bytes
File C:\RRbackups\C\0\Data212 50003968 bytes
File C:\RRbackups\C\0\Data213 50003968 bytes
File C:\RRbackups\C\0\Data214 50003968 bytes
File C:\RRbackups\C\0\Data215 50003968 bytes
File C:\RRbackups\C\0\Data216 50003968 bytes
File C:\RRbackups\C\0\Data217 50003968 bytes
File C:\RRbackups\C\0\Data218 50003968 bytes
File C:\RRbackups\C\0\Data219 50003968 bytes
File C:\RRbackups\C\0\Data22 50003968 bytes
File C:\RRbackups\C\0\Data220 50003968 bytes
File C:\RRbackups\C\0\Data221 50003968 bytes
File C:\RRbackups\C\0\Data222 50003968 bytes
File C:\RRbackups\C\0\Data223 50003968 bytes
File C:\RRbackups\C\0\Data224 50003968 bytes
File C:\RRbackups\C\0\Data225 50003968 bytes
File C:\RRbackups\C\0\Data226 50003968 bytes
File C:\RRbackups\C\0\Data227 50003968 bytes
File C:\RRbackups\C\0\Data228 50003968 bytes
File C:\RRbackups\C\0\Data229 50003968 bytes
File C:\RRbackups\C\0\Data230 50003968 bytes
File C:\RRbackups\C\0\Data231 50003968 bytes
File C:\RRbackups\C\0\Data232 50003968 bytes
File C:\RRbackups\C\0\Data233 50003968 bytes
File C:\RRbackups\C\0\Data234 50003968 bytes
File C:\RRbackups\C\0\Data235 50003968 bytes
File C:\RRbackups\C\0\Data236 50003968 bytes
File C:\RRbackups\C\0\Data237 50003968 bytes
File C:\RRbackups\C\0\Data238 50003968 bytes
File C:\RRbackups\C\0\Data239 50003968 bytes
File C:\RRbackups\C\0\Data24 50003968 bytes
File C:\RRbackups\C\0\Data240 50003968 bytes
File C:\RRbackups\C\0\Data241 50003968 bytes
File C:\RRbackups\C\0\Data242 50003968 bytes
File C:\RRbackups\C\0\Data243 50003968 bytes
File C:\RRbackups\C\0\Data244 50003968 bytes
File C:\RRbackups\C\0\Data245 50003968 bytes
File C:\RRbackups\C\0\Data246 50003968 bytes
File C:\RRbackups\C\0\Data247 50003968 bytes
File C:\RRbackups\C\0\Data248 50003968 bytes
File C:\RRbackups\C\0\Data25 50003968 bytes
File C:\RRbackups\C\0\Data250 50003968 bytes
File C:\RRbackups\C\0\Data251 50003968 bytes
File C:\RRbackups\C\0\Data252 50003968 bytes
File C:\RRbackups\C\0\Data253 50003968 bytes
File C:\RRbackups\C\0\Data254 50003968 bytes
File C:\RRbackups\C\0\Data255 50003968 bytes
File C:\RRbackups\C\0\Data256 50003968 bytes
File C:\RRbackups\C\0\Data257 50003968 bytes
File C:\RRbackups\C\0\Data258 50003968 bytes
File C:\RRbackups\C\0\Data259 50003968 bytes
File C:\RRbackups\C\0\Data26 50003968 bytes
File C:\RRbackups\C\0\Data260 50003968 bytes
File C:\RRbackups\C\0\Data261 50003968 bytes
File C:\RRbackups\C\0\Data262 50003968 bytes
File C:\RRbackups\C\0\Data263 50003968 bytes
File C:\RRbackups\C\0\Data264 50003968 bytes
File C:\RRbackups\C\0\Data265 50003968 bytes
File C:\RRbackups\C\0\Data266 50003968 bytes
File C:\RRbackups\C\0\Data267 50003968 bytes
File C:\RRbackups\C\0\Data268 50003968 bytes
File C:\RRbackups\C\0\Data269 50003968 bytes
File C:\RRbackups\C\0\Data29 50003968 bytes
File C:\RRbackups\C\0\Data290 50003968 bytes
File C:\RRbackups\C\0\Data291 50003968 bytes
File C:\RRbackups\C\0\Data292 50003968 bytes
File C:\RRbackups\C\0\Data293 50003968 bytes
File C:\RRbackups\C\0\Data294 50003968 bytes
File C:\RRbackups\C\0\Data295 50003968 bytes
File C:\RRbackups\C\0\Data296 50003968 bytes
File C:\RRbackups\C\0\Data297 50003968 bytes
File C:\RRbackups\C\0\Data298 50003968 bytes
File C:\RRbackups\C\0\Data299 50003968 bytes
File C:\RRbackups\C\0\Data3 50003968 bytes
File C:\RRbackups\C\0\Data30 50003968 bytes
File C:\RRbackups\C\0\Data300 50003968 bytes
File C:\RRbackups\C\0\Data301 50003968 bytes
File C:\RRbackups\C\0\Data302 50003968 bytes
File C:\RRbackups\C\0\Data303 50003968 bytes
File C:\RRbackups\C\0\Data304 50003968 bytes
File C:\RRbackups\C\0\Data305 50003968 bytes
File C:\RRbackups\C\0\Data306 50003968 bytes
File C:\RRbackups\C\0\Data308 50003968 bytes
File C:\RRbackups\C\0\Data309 50003968 bytes
File C:\RRbackups\C\0\Data31 50003968 bytes
File C:\RRbackups\C\0\Data310 50003968 bytes
File C:\RRbackups\C\0\Data311 50003968 bytes
File C:\RRbackups\C\0\Data312 50003968 bytes
File C:\RRbackups\C\0\Data313 50003968 bytes
File C:\RRbackups\C\0\Data314 50003968 bytes
File C:\RRbackups\C\0\Data315 50003968 bytes
File C:\RRbackups\C\0\Data316 50003968 bytes
File C:\RRbackups\C\0\Data317 50003968 bytes
File C:\RRbackups\C\0\Data318 50003968 bytes
File C:\RRbackups\C\0\Data319 50003968 bytes
File C:\RRbackups\C\0\Data32 50003968 bytes
File C:\RRbackups\C\0\Data320 50003968 bytes
File C:\RRbackups\C\0\Data321 50003968 bytes
File C:\RRbackups\C\0\Data322 50003968 bytes
File C:\RRbackups\C\0\Data323 50003968 bytes
File C:\RRbackups\C\0\Data324 50003968 bytes
File C:\RRbackups\C\0\Data325 50003968 bytes
File C:\RRbackups\C\0\Data327 50003968 bytes
File C:\RRbackups\C\0\Data328 50003968 bytes
File C:\RRbackups\C\0\Data329 50003968 bytes
File C:\RRbackups\C\0\Data33 50003968 bytes
File C:\RRbackups\C\0\Data330 50003968 bytes
File C:\RRbackups\C\0\Data331 50003968 bytes
File C:\RRbackups\C\0\Data332 50003968 bytes
File C:\RRbackups\C\0\Data333 50003968 bytes
File C:\RRbackups\C\0\Data334 50003968 bytes
File C:\RRbackups\C\0\Data335 50003968 bytes
File C:\RRbackups\C\0\Data336 50003968 bytes
File C:\RRbackups\C\0\Data337 50003968 bytes
File C:\RRbackups\C\0\Data338 50003968 bytes
File C:\RRbackups\C\0\Data339 50003968 bytes
File C:\RRbackups\C\0\Data34 50003968 bytes
File C:\RRbackups\C\0\Data340 50003968 bytes
File C:\RRbackups\C\0\Data341 50003968 bytes
File C:\RRbackups\C\0\Data342 50003968 bytes
File C:\RRbackups\C\0\Data343 50003968 bytes
File C:\RRbackups\C\0\Data344 50003968 bytes
File C:\RRbackups\C\0\Data346 50003968 bytes
File C:\RRbackups\C\0\Data347 50003968 bytes
File C:\RRbackups\C\0\Data348 50003968 bytes
File C:\RRbackups\C\0\Data349 50003968 bytes
File C:\RRbackups\C\0\Data35 50003968 bytes
File C:\RRbackups\C\0\Data350 50003968 bytes
File C:\RRbackups\C\0\Data351 50003968 bytes
File C:\RRbackups\C\0\Data352 50003968 bytes
File C:\RRbackups\C\0\Data353 50003968 bytes
File C:\RRbackups\C\0\Data354 50003968 bytes
File C:\RRbackups\C\0\Data355 50003968 bytes
File C:\RRbackups\C\0\Data356 50003968 bytes
File C:\RRbackups\C\0\Data357 50003968 bytes
File C:\RRbackups\C\0\Data358 50003968 bytes
File C:\RRbackups\C\0\Data359 50003968 bytes
File C:\RRbackups\C\0\Data36 50003968 bytes
File C:\RRbackups\C\0\Data360 50003968 bytes
File C:\RRbackups\C\0\Data361 50003968 bytes
File C:\RRbackups\C\0\Data362 50003968 bytes
File C:\RRbackups\C\0\Data363 50003968 bytes
File C:\RRbackups\C\0\Data365 50003968 bytes
File C:\RRbackups\C\0\Data366 50003968 bytes
File C:\RRbackups\C\0\Data367 50003968 bytes
File C:\RRbackups\C\0\Data368 50003968 bytes
File C:\RRbackups\C\0\Data369 50003968 bytes
File C:\RRbackups\C\0\Data37 50003968 bytes
File C:\RRbackups\C\0\Data370 50003968 bytes
File C:\RRbackups\C\0\Data371 50003968 bytes
File C:\RRbackups\C\0\Data372 50003968 bytes
File C:\RRbackups\C\0\Data373 50003968 bytes
File C:\RRbackups\C\0\Data374 50003968 bytes
File C:\RRbackups\C\0\Data375 50003968 bytes
File C:\RRbackups\C\0\Data376 50003968 bytes
File C:\RRbackups\C\0\Data377 50003968 bytes
File C:\RRbackups\C\0\Data378 50003968 bytes
File C:\RRbackups\C\0\Data379 50003968 bytes
File C:\RRbackups\C\0\Data38 50003968 bytes
File C:\RRbackups\C\0\Data380 50003968 bytes
File C:\RRbackups\C\0\Data381 50003968 bytes
File C:\RRbackups\C\0\Data382 50003968 bytes
File C:\RRbackups\C\0\Data384 50003968 bytes
File C:\RRbackups\C\0\Data385 50003968 bytes
File C:\RRbackups\C\0\Data386 50003968 bytes
File C:\RRbackups\C\0\Data387 50003968 bytes
File C:\RRbackups\C\0\Data388 50003968 bytes
File C:\RRbackups\C\0\Data389 50003968 bytes
File C:\RRbackups\C\0\Data39 50003968 bytes
File C:\RRbackups\C\0\Data390 50003968 bytes
File C:\RRbackups\C\0\Data391 50003968 bytes
File C:\RRbackups\C\0\Data392 50003968 bytes
File C:\RRbackups\C\0\Data393 50003968 bytes
File C:\RRbackups\C\0\Data394 50003968 bytes
File C:\RRbackups\C\0\Data395 50003968 bytes
File C:\RRbackups\C\0\Data396 50003968 bytes
File C:\RRbackups\C\0\Data397 50003968 bytes
File C:\RRbackups\C\0\Data398 50003968 bytes
File C:\RRbackups\C\0\Data399 50003968 bytes
File C:\RRbackups\C\0\Data4 50003968 bytes
File C:\RRbackups\C\0\Data40 50003968 bytes
File C:\RRbackups\C\0\Data400 50003968 bytes
File C:\RRbackups\C\0\Data402 50003968 bytes
File C:\RRbackups\C\0\Data403 50003968 bytes
File C:\RRbackups\C\0\Data404 50003968 bytes
File C:\RRbackups\C\0\Data405 50003968 bytes
File C:\RRbackups\C\0\Data406 50003968 bytes
File C:\RRbackups\C\0\Data407 50003968 bytes
File C:\RRbackups\C\0\Data408 50003968 bytes
File C:\RRbackups\C\0\Data409 50003968 bytes
File C:\RRbackups\C\0\Data41 50003968 bytes
File C:\RRbackups\C\0\Data410 50003968 bytes
File C:\RRbackups\C\0\Data411 50003968 bytes
File C:\RRbackups\C\0\Data412 50003968 bytes
File C:\RRbackups\C\0\Data413 50003968 bytes
File C:\RRbackups\C\0\Data414 50003968 bytes
File C:\RRbackups\C\0\Data415 50003968 bytes
File C:\RRbackups\C\0\Data416 50003968 bytes
File C:\RRbackups\C\0\Data417 50003968 bytes
File C:\RRbackups\C\0\Data418 50003968 bytes
File C:\RRbackups\C\0\Data419 50003968 bytes
File C:\RRbackups\C\0\Data42 50003968 bytes
File C:\RRbackups\C\0\Data421 50003968 bytes
File C:\RRbackups\C\0\Data422 50003968 bytes
File C:\RRbackups\C\0\Data423 50003968 bytes
File C:\RRbackups\C\0\Data424 50003968 bytes
File C:\RRbackups\C\0\Data425 50003968 bytes
File C:\RRbackups\C\0\Data426 50003968 bytes
File C:\RRbackups\C\0\Data427 50003968 bytes
File C:\RRbackups\C\0\Data428 50003968 bytes
File C:\RRbackups\C\0\Data429 50003968 bytes
File C:\RRbackups\C\0\Data43 50003968 bytes
File C:\RRbackups\C\0\Data430 50003968 bytes
File C:\RRbackups\C\0\Data431 50003968 bytes
File C:\RRbackups\C\0\Data432 50003968 bytes
File C:\RRbackups\C\0\Data433 50003968 bytes
File C:\RRbackups\C\0\Data434 50003968 bytes
File C:\RRbackups\C\0\Data435 50003968 bytes
File C:\RRbackups\C\0\Data436 50003968 bytes
File C:\RRbackups\C\0\Data437 50003968 bytes
File C:\RRbackups\C\0\Data438 50003968 bytes
File C:\RRbackups\C\0\Data439 50003968 bytes
File C:\RRbackups\C\0\Data440 50003968 bytes
File C:\RRbackups\C\0\Data441 50003968 bytes
File C:\RRbackups\C\0\Data442 50003968 bytes
File C:\RRbackups\C\0\Data443 50003968 bytes
File C:\RRbackups\C\0\Data444 50003968 bytes
File C:\RRbackups\C\0\Data445 50003968 bytes
File C:\RRbackups\C\0\Data446 50003968 bytes
File C:\RRbackups\C\0\Data447 50003968 bytes
File C:\RRbackups\C\0\Data448 50003968 bytes
File C:\RRbackups\C\0\Data449 50003968 bytes
File C:\RRbackups\C\0\Data45 50003968 bytes
File C:\RRbackups\C\0\Data450 50003968 bytes
File C:\RRbackups\C\0\Data451 50003968 bytes
File C:\RRbackups\C\0\Data452 50003968 bytes
File C:\RRbackups\C\0\Data453 50003968 bytes
File C:\RRbackups\C\0\Data454 50003968 bytes
File C:\RRbackups\C\0\Data455 50003968 bytes
File C:\RRbackups\C\0\Data456 50003968 bytes
File C:\RRbackups\C\0\Data457 50003968 bytes
File C:\RRbackups\C\0\Data458 50003968 bytes
File C:\RRbackups\C\0\Data459 50003968 bytes
File C:\RRbackups\C\0\Data48 50003968 bytes
File C:\RRbackups\C\0\Data480 50003968 bytes
File C:\RRbackups\C\0\Data481 50003968 bytes
File C:\RRbackups\C\0\Data482 50003968 bytes
File C:\RRbackups\C\0\Data483 50003968 bytes
File C:\RRbackups\C\0\Data484 50003968 bytes
File C:\RRbackups\C\0\Data485 50003968 bytes
File C:\RRbackups\C\0\Data486 50003968 bytes
File C:\RRbackups\C\0\Data487 50003968 bytes
File C:\RRbackups\C\0\Data488 50003968 bytes
File C:\RRbackups\C\0\Data489 50003968 bytes
File C:\RRbackups\C\0\Data49 50003968 bytes
File C:\RRbackups\C\0\Data490 50003968 bytes
File C:\RRbackups\C\0\Data491 50003968 bytes
File C:\RRbackups\C\0\Data492 50003968 bytes
File C:\RRbackups\C\0\Data493 50003968 bytes
File C:\RRbackups\C\0\Data494 50003968 bytes
File C:\RRbackups\C\0\Data495 50003968 bytes
File C:\RRbackups\C\0\Data496 50003968 bytes
File C:\RRbackups\C\0\Data497 50003968 bytes
File C:\RRbackups\C\0\Data499 50003968 bytes
File C:\RRbackups\C\0\Data5 50003968 bytes
File C:\RRbackups\C\0\Data50 50003968 bytes
File C:\RRbackups\C\0\Data500 50003968 bytes
File C:\RRbackups\C\0\Data501 50003968 bytes
File C:\RRbackups\C\0\Data502 50003968 bytes
File C:\RRbackups\C\0\Data503 50003968 bytes
File C:\RRbackups\C\0\Data504 50003968 bytes
File C:\RRbackups\C\0\Data505 50003968 bytes
File C:\RRbackups\C\0\Data506 50003968 bytes
File C:\RRbackups\C\0\Data507 50003968 bytes
File C:\RRbackups\C\0\Data508 50003968 bytes
File C:\RRbackups\C\0\Data509 50003968 bytes
File C:\RRbackups\C\0\Data51 50003968 bytes
File C:\RRbackups\C\0\Data510 50003968 bytes
File C:\RRbackups\C\0\Data511 50003968 bytes
File C:\RRbackups\C\0\Data512 50003968 bytes
File C:\RRbackups\C\0\Data513 50003968 bytes
File C:\RRbackups\C\0\Data514 50003968 bytes
File C:\RRbackups\C\0\Data515 50003968 bytes
File C:\RRbackups\C\0\Data517 50003968 bytes
File C:\RRbackups\C\0\Data518 50003968 bytes
File C:\RRbackups\C\0\Data519 50003968 bytes
File C:\RRbackups\C\0\Data52 50003968 bytes
File C:\RRbackups\C\0\Data520 50003968 bytes
File C:\RRbackups\C\0\Data521 50003968 bytes
File C:\RRbackups\C\0\Data522 50003968 bytes
File C:\RRbackups\C\0\Data523 50003968 bytes
File C:\RRbackups\C\0\Data524 50003968 bytes
File C:\RRbackups\C\0\Data525 50003968 bytes
File C:\RRbackups\C\0\Data526 50003968 bytes
File C:\RRbackups\C\0\Data527 50003968 bytes
File C:\RRbackups\C\0\Data528 50003968 bytes
File C:\RRbackups\C\0\Data529 50003968 bytes
File C:\RRbackups\C\0\Data53 50003968 bytes
File C:\RRbackups\C\0\Data530 50003968 bytes
File C:\RRbackups\C\0\Data531 50003968 bytes
File C:\RRbackups\C\0\Data532 50003968 bytes
File C:\RRbackups\C\0\Data533 50003968 bytes
File C:\RRbackups\C\0\Data534 50003968 bytes
File C:\RRbackups\C\0\Data536 50003968 bytes
File C:\RRbackups\C\0\Data537 50003968 bytes
File C:\RRbackups\C\0\Data538 50003968 bytes
File C:\RRbackups\C\0\Data539 50003968 bytes
File C:\RRbackups\C\0\Data54 50003968 bytes
File C:\RRbackups\C\0\Data540 50003968 bytes
File C:\RRbackups\C\0\Data541 50003968 bytes
File C:\RRbackups\C\0\Data542 50003968 bytes
File C:\RRbackups\C\0\Data543 50003968 bytes
File C:\RRbackups\C\0\Data544 50003968 bytes
File C:\RRbackups\C\0\Data545 50003968 bytes
File C:\RRbackups\C\0\Data546 50003968 bytes
File C:\RRbackups\C\0\Data547 50003968 bytes
File C:\RRbackups\C\0\Data548 50003968 bytes
File C:\RRbackups\C\0\Data549 50003968 bytes
File C:\RRbackups\C\0\Data55 50003968 bytes
File C:\RRbackups\C\0\Data550 50003968 bytes
File C:\RRbackups\C\0\Data551 50003968 bytes
File C:\RRbackups\C\0\Data552 50003968 bytes
File C:\RRbackups\C\0\Data553 50003968 bytes
File C:\RRbackups\C\0\Data555 50003968 bytes
File C:\RRbackups\C\0\Data556 50003968 bytes
File C:\RRbackups\C\0\Data557 50003968 bytes
File C:\RRbackups\C\0\Data558 50003968 bytes
File C:\RRbackups\C\0\Data559 50003968 bytes
File C:\RRbackups\C\0\Data56 50003968 bytes
File C:\RRbackups\C\0\Data560 50003968 bytes
File C:\RRbackups\C\0\Data561 50003968 bytes
File C:\RRbackups\C\0\Data562 50003968 bytes
File C:\RRbackups\C\0\Data563 50003968 bytes
File C:\RRbackups\C\0\Data564 50003968 bytes
File C:\RRbackups\C\0\Data565 50003968 bytes
File C:\RRbackups\C\0\Data566 50003968 bytes
File C:\RRbackups\C\0\Data567 50003968 bytes
File C:\RRbackups\C\0\Data568 50003968 bytes
File C:\RRbackups\C\0\Data569 50003968 bytes
File C:\RRbackups\C\0\Data57 50003968 bytes
File C:\RRbackups\C\0\Data570 50003968 bytes
File C:\RRbackups\C\0\Data571 50003968 bytes
File C:\RRbackups\C\0\Data572 50003968 bytes
File C:\RRbackups\C\0\Data574 50003968 bytes
File C:\RRbackups\C\0\Data575 50003968 bytes
File C:\RRbackups\C\0\Data576 50003968 bytes
File C:\RRbackups\C\0\Data577 50003968 bytes
File C:\RRbackups\C\0\Data578 50003968 bytes
File C:\RRbackups\C\0\Data579 50003968 bytes
File C:\RRbackups\C\0\Data58 50003968 bytes
File C:\RRbackups\C\0\Data580 50003968 bytes
File C:\RRbackups\C\0\Data581 50003968 bytes
File C:\RRbackups\C\0\Data582 50003968 bytes
File C:\RRbackups\C\0\Data583 50003968 bytes
File C:\RRbackups\C\0\Data584 50003968 bytes
File C:\RRbackups\C\0\Data585 50003968 bytes
File C:\RRbackups\C\0\Data586 50003968 bytes
File C:\RRbackups\C\0\Data587 50003968 bytes
File C:\RRbackups\C\0\Data588 50003968 bytes
File C:\RRbackups\C\0\Data589 50003968 bytes
File C:\RRbackups\C\0\Data59 50003968 bytes
File C:\RRbackups\C\0\Data590 50003968 bytes
File C:\RRbackups\C\0\Data591 50003968 bytes
File C:\RRbackups\C\0\Data593 50003968 bytes
File C:\RRbackups\C\0\Data594 50003968 bytes
File C:\RRbackups\C\0\Data595 50003968 bytes
File C:\RRbackups\C\0\Data596 50003968 bytes
File C:\RRbackups\C\0\Data597 50003968 bytes
File C:\RRbackups\C\0\Data598 50003968 bytes
File C:\RRbackups\C\0\Data599 50003968 bytes
File C:\RRbackups\C\0\Data6 50003968 bytes
File C:\RRbackups\C\0\Data60 50003968 bytes
File C:\RRbackups\C\0\Data600 50003968 bytes
File C:\RRbackups\C\0\Data601 50003968 bytes
File C:\RRbackups\C\0\Data602 50003968 bytes
File C:\RRbackups\C\0\Data603 50003968 bytes
File C:\RRbackups\C\0\Data604 50003968 bytes
File C:\RRbackups\C\0\Data605 50003968 bytes
File C:\RRbackups\C\0\Data606 50003968 bytes
File C:\RRbackups\C\0\Data607 50003968 bytes
File C:\RRbackups\C\0\Data608 50003968 bytes
File C:\RRbackups\C\0\Data609 50003968 bytes
File C:\RRbackups\C\0\Data61 50003968 bytes
File C:\RRbackups\C\0\Data611 50003968 bytes
File C:\RRbackups\C\0\Data612 50003968 bytes
File C:\RRbackups\C\0\Data613 50003968 bytes
File C:\RRbackups\C\0\Data614 50003968 bytes
File C:\RRbackups\C\0\Data615 50003968 bytes
File C:\RRbackups\C\0\Data616 50003968 bytes
File C:\RRbackups\C\0\Data617 50003968 bytes
File C:\RRbackups\C\0\Data618 50003968 bytes
File C:\RRbackups\C\0\Data619 50003968 bytes
File C:\RRbackups\C\0\Data62 50003968 bytes
File C:\RRbackups\C\0\Data620 50003968 bytes
File C:\RRbackups\C\0\Data621 50003968 bytes
File C:\RRbackups\C\0\Data622 50003968 bytes
File C:\RRbackups\C\0\Data623 50003968 bytes
File C:\RRbackups\C\0\Data624 50003968 bytes
File C:\RRbackups\C\0\Data625 50003968 bytes
File C:\RRbackups\C\0\Data626 50003968 bytes
File C:\RRbackups\C\0\Data627 50003968 bytes
File C:\RRbackups\C\0\Data628 50003968 bytes
File C:\RRbackups\C\0\Data629 50003968 bytes
File C:\RRbackups\C\0\Data630 50003968 bytes
File C:\RRbackups\C\0\Data631 50003968 bytes
File C:\RRbackups\C\0\Data632 50003968 bytes
File C:\RRbackups\C\0\Data633 50003968 bytes
File C:\RRbackups\C\0\Data634 50003968 bytes
File C:\RRbackups\C\0\Data635 50003968 bytes
File C:\RRbackups\C\0\Data636 50003968 bytes
File C:\RRbackups\C\0\Data637 50003968 bytes
File C:\RRbackups\C\0\Data638 50003968 bytes
File C:\RRbackups\C\0\Data639 50003968 bytes
File C:\RRbackups\C\0\Data64 50003968 bytes
File C:\RRbackups\C\0\Data640 50003968 bytes
File C:\RRbackups\C\0\Data641 50003968 bytes
File C:\RRbackups\C\0\Data642 50003968 bytes
File C:\RRbackups\C\0\Data643 50003968 bytes
File C:\RRbackups\C\0\Data644 50003968 bytes
File C:\RRbackups\C\0\Data645 50003968 bytes
File C:\RRbackups\C\0\Data646 50003968 bytes
File C:\RRbackups\C\0\Data647 50003968 bytes
File C:\RRbackups\C\0\Data648 50003968 bytes
File C:\RRbackups\C\0\Data649 50003968 bytes
File C:\RRbackups\C\0\Data840 50003968 bytes
File C:\RRbackups\C\0\Data841 50003968 bytes
File C:\RRbackups\C\0\Data842 50003968 bytes
File C:\RRbackups\C\0\Data843 50003968 bytes
File C:\RRbackups\C\0\Data844 50003968 bytes
File C:\RRbackups\C\0\Data845 50003968 bytes
File C:\RRbackups\C\0\Data846 50003968 bytes
File C:\RRbackups\C\0\Data847 50003968 bytes
File C:\RRbackups\C\0\Data848 50003968 bytes
File C:\RRbackups\C\0\Data849 50003968 bytes
File C:\RRbackups\C\0\Data85 50003968 bytes
File C:\RRbackups\C\0\Data850 50003968 bytes
File C:\RRbackups\C\0\Data851 50003968 bytes
File C:\RRbackups\C\0\Data852 50003968 bytes
File C:\RRbackups\C\0\Data853 50003968 bytes
File C:\RRbackups\C\0\Data854 50003968 bytes
File C:\RRbackups\C\0\Data855 50003968 bytes
File C:\RRbackups\C\0\Data856 50003968 bytes
File C:\RRbackups\C\0\Data857 50003968 bytes
File C:\RRbackups\C\0\Data858 50003968 bytes
File C:\RRbackups\C\0\Data67 50003968 bytes
File C:\RRbackups\C\0\Data670 50003968 bytes
File C:\RRbackups\C\0\Data671 50003968 bytes
File C:\RRbackups\C\0\Data672 50003968 bytes
File C:\RRbackups\C\0\Data673 50003968 bytes
File C:\RRbackups\C\0\Data674 50003968 bytes
File C:\RRbackups\C\0\Data675 50003968 bytes
File C:\RRbackups\C\0\Data676 50003968 bytes
File C:\RRbackups\C\0\Data677 50003968 bytes
File C:\RRbackups\C\0\Data678 50003968 bytes
File C:\RRbackups\C\0\Data679 50003968 bytes
File C:\RRbackups\C\0\Data68 50003968 bytes
File C:\RRbackups\C\0\Data680 50003968 bytes
File C:\RRbackups\C\0\Data681 50003968 bytes
File C:\RRbackups\C\0\Data682 50003968 bytes
File C:\RRbackups\C\0\Data683 50003968 bytes
File C:\RRbackups\C\0\Data684 50003968 bytes
File C:\RRbackups\C\0\Data685 50003968 bytes
File C:\RRbackups\C\0\Data686 50003968 bytes
File C:\RRbackups\C\0\Data687 50003968 bytes
File C:\RRbackups\C\0\Data689 50003968 bytes
File C:\RRbackups\C\0\Data69 50003968 bytes
File C:\RRbackups\C\0\Data690 50003968 bytes
File C:\RRbackups\C\0\Data691 50003968 bytes
File C:\RRbackups\C\0\Data692 50003968 bytes
File C:\RRbackups\C\0\Data693 50003968 bytes
File C:\RRbackups\C\0\Data694 50003968 bytes
File C:\RRbackups\C\0\Data695 50003968 bytes
File C:\RRbackups\C\0\Data696 50003968 bytes
File C:\RRbackups\C\0\Data697 50003968 bytes
File C:\RRbackups\C\0\Data698 50003968 bytes
File C:\RRbackups\C\0\Data699 50003968 bytes
File C:\RRbackups\C\0\Data7 50003968 bytes
File C:\RRbackups\C\0\Data70 50003968 bytes
File C:\RRbackups\C\0\Data700 50003968 bytes
File C:\RRbackups\C\0\Data701 50003968 bytes
File C:\RRbackups\C\0\Data702 50003968 bytes
File C:\RRbackups\C\0\Data703 50003968 bytes
File C:\RRbackups\C\0\Data704 50003968 bytes
File C:\RRbackups\C\0\Data705 50003968 bytes
File C:\RRbackups\C\0\Data707 50003968 bytes
File C:\RRbackups\C\0\Data708 50003968 bytes
File C:\RRbackups\C\0\Data709 50003968 bytes
File C:\RRbackups\C\0\Data71 50003968 bytes
File C:\RRbackups\C\0\Data710 50003968 bytes
File C:\RRbackups\C\0\Data711 50003968 bytes
File C:\RRbackups\C\0\Data712 50003968 bytes
File C:\RRbackups\C\0\Data713 50003968 bytes
File C:\RRbackups\C\0\Data714 50003968 bytes
File C:\RRbackups\C\0\Data715 50003968 bytes
File C:\RRbackups\C\0\Data716 50003968 bytes
File C:\RRbackups\C\0\Data717 50003968 bytes
File C:\RRbackups\C\0\Data718 50003968 bytes
File C:\RRbackups\C\0\Data719 50003968 bytes
File C:\RRbackups\C\0\Data72 50003968 bytes
File C:\RRbackups\C\0\Data720 50003968 bytes
File C:\RRbackups\C\0\Data721 50003968 bytes
File C:\RRbackups\C\0\Data722 50003968 bytes
File C:\RRbackups\C\0\Data723 50003968 bytes
File C:\RRbackups\C\0\Data724 50003968 bytes
File C:\RRbackups\C\0\Data726 50003968 bytes
File C:\RRbackups\C\0\Data727 50003968 bytes
File C:\RRbackups\C\0\Data728 50003968 bytes
File C:\RRbackups\C\0\Data729 50003968 bytes
File C:\RRbackups\C\0\Data73 50003968 bytes
File C:\RRbackups\C\0\Data730 50003968 bytes
File C:\RRbackups\C\0\Data731 50003968 bytes
File C:\RRbackups\C\0\Data732 50003968 bytes
File C:\RRbackups\C\0\Data733 50003968 bytes
File C:\RRbackups\C\0\Data734 50003968 bytes
File C:\RRbackups\C\0\Data735 50003968 bytes
File C:\RRbackups\C\0\Data736 50003968 bytes
File C:\RRbackups\C\0\Data737 50003968 bytes
File C:\RRbackups\C\0\Data738 50003968 bytes
File C:\RRbackups\C\0\Data739 50003968 bytes
File C:\RRbackups\C\0\Data74 50003968 bytes
File C:\RRbackups\C\0\Data740 50003968 bytes
File C:\RRbackups\C\0\Data741 50003968 bytes
File C:\RRbackups\C\0\Data742 50003968 bytes
File C:\RRbackups\C\0\Data743 50003968 bytes
File C:\RRbackups\C\0\Data745 50003968 bytes
File C:\RRbackups\C\0\Data746 50003968 bytes
File C:\RRbackups\C\0\Data747 50003968 bytes
File C:\RRbackups\C\0\Data748 50003968 bytes
File C:\RRbackups\C\0\Data749 50003968 bytes
File C:\RRbackups\C\0\Data75 50003968 bytes
File C:\RRbackups\C\0\Data750 50003968 bytes
File C:\RRbackups\C\0\Data751 50003968 bytes
File C:\RRbackups\C\0\Data752 50003968 bytes
File C:\RRbackups\C\0\Data753 50003968 bytes
File C:\RRbackups\C\0\Data754 50003968 bytes
File C:\RRbackups\C\0\Data755 50003968 bytes
File C:\RRbackups\C\0\Data756 50003968 bytes
File C:\RRbackups\C\0\Data757 50003968 bytes
File C:\RRbackups\C\0\Data758 50003968 bytes
File C:\RRbackups\C\0\Data759 50003968 bytes
File C:\RRbackups\C\0\Data76 50003968 bytes
File C:\RRbackups\C\0\Data760 50003968 bytes
File C:\RRbackups\C\0\Data761 50003968 bytes
File C:\RRbackups\C\0\Data762 50003968 bytes
File C:\RRbackups\C\0\Data764 50003968 bytes
File C:\RRbackups\C\0\Data765 50003968 bytes
File C:\RRbackups\C\0\Data766 50003968 bytes
File C:\RRbackups\C\0\Data767 50003968 bytes
File C:\RRbackups\C\0\Data768 50003968 bytes
File C:\RRbackups\C\0\Data769 50003968 bytes
File C:\RRbackups\C\0\Data77 50003968 bytes
File C:\RRbackups\C\0\Data770 50003968 bytes
File C:\RRbackups\C\0\Data771 50003968 bytes
File C:\RRbackups\C\0\Data772 50003968 bytes
File C:\RRbackups\C\0\Data773 50003968 bytes
File C:\RRbackups\C\0\Data774 50003968 bytes
File C:\RRbackups\C\0\Data775 50003968 bytes
File C:\RRbackups\C\0\Data776 50003968 bytes
File C:\RRbackups\C\0\Data777 50003968 bytes
File C:\RRbackups\C\0\Data778 50003968 bytes
File C:\RRbackups\C\0\Data779 50003968 bytes
File C:\RRbackups\C\0\Data78 50003968 bytes
File C:\RRbackups\C\0\Data780 50003968 bytes
File C:\RRbackups\C\0\Data781 50003968 bytes
File C:\RRbackups\C\0\Data783 50003968 bytes
File C:\RRbackups\C\0\Data784 50003968 bytes
File C:\RRbackups\C\0\Data785 50003968 bytes
File C:\RRbackups\C\0\Data786 50003968 bytes
File C:\RRbackups\C\0\Data787 50003968 bytes
File C:\RRbackups\C\0\Data788 50003968 bytes
File C:\RRbackups\C\0\Data789 50003968 bytes
File C:\RRbackups\C\0\Data79 50003968 bytes
File C:\RRbackups\C\0\Data790 50003968 bytes
File C:\RRbackups\C\0\Data791 50003968 bytes
File C:\RRbackups\C\0\Data792 50003968 bytes
File C:\RRbackups\C\0\Data793 50003968 bytes
File C:\RRbackups\C\0\Data794 50003968 bytes
File C:\RRbackups\C\0\Data795 50003968 bytes
File C:\RRbackups\C\0\Data796 50003968 bytes
File C:\RRbackups\C\0\Data797 50003968 bytes
File C:\RRbackups\C\0\Data798 50003968 bytes
File C:\RRbackups\C\0\Data799 50003968 bytes
File C:\RRbackups\C\0\Data8 50003968 bytes
File C:\RRbackups\C\0\Data80 50003968 bytes
File C:\RRbackups\C\0\Data801 50003968 bytes
File C:\RRbackups\C\0\Data802 50003968 bytes
File C:\RRbackups\C\0\Data803 50003968 bytes
File C:\RRbackups\C\0\Data804 50003968 bytes
File C:\RRbackups\C\0\Data805 50003968 bytes
File C:\RRbackups\C\0\Data806 50003968 bytes
File C:\RRbackups\C\0\Data807 50003968 bytes
File C:\RRbackups\C\0\Data808 50003968 bytes
File C:\RRbackups\C\0\Data809 50003968 bytes
File C:\RRbackups\C\0\Data81 50003968 bytes
File C:\RRbackups\C\0\Data810 50003968 bytes
File C:\RRbackups\C\0\Data811 50003968 bytes
File C:\RRbackups\C\0\Data812 50003968 bytes
File C:\RRbackups\C\0\Data813 50003968 bytes
File C:\RRbackups\C\0\Data814 50003968 bytes
File C:\RRbackups\C\0\Data815 50003968 bytes
File C:\RRbackups\C\0\Data816 50003968 bytes
File C:\RRbackups\C\0\Data817 50003968 bytes
File C:\RRbackups\C\0\Data818 50003968 bytes
File C:\RRbackups\C\0\Data819 50003968 bytes
File C:\RRbackups\C\0\Data820 50003968 bytes
File C:\RRbackups\C\0\Data821 50003968 bytes
File C:\RRbackups\C\0\Data822 50003968 bytes
File C:\RRbackups\C\0\Data823 50003968 bytes
File C:\RRbackups\C\0\Data824 50003968 bytes
File C:\RRbackups\C\0\Data825 50003968 bytes
File C:\RRbackups\C\0\Data826 50003968 bytes
File C:\RRbackups\C\0\Data827 50003968 bytes
File C:\RRbackups\C\0\Data828 50003968 bytes
File C:\RRbackups\C\0\Data829 50003968 bytes
File C:\RRbackups\C\0\Data83 50003968 bytes
File C:\RRbackups\C\0\Data830 50003968 bytes
File C:\RRbackups\C\0\Data831 50003968 bytes
File C:\RRbackups\C\0\Data832 50003968 bytes
File C:\RRbackups\C\0\Data833 50003968 bytes
File C:\RRbackups\C\0\Data834 50003968 bytes
File C:\RRbackups\C\0\Data835 50003968 bytes
File C:\RRbackups\C\0\Data836 50003968 bytes
File C:\RRbackups\C\0\Data837 50003968 bytes
File C:\RRbackups\C\0\Data838 50003968 bytes
File C:\RRbackups\C\0\Data839 50003968 bytes
File C:\RRbackups\C\0\Data498 50003968 bytes
File C:\RRbackups\C\0\Data516 50003968 bytes
File C:\RRbackups\C\0\Data535 50003968 bytes
File C:\RRbackups\C\0\Data554 50003968 bytes
File C:\RRbackups\C\0\Data573 50003968 bytes
File C:\RRbackups\C\0\Data592 50003968 bytes
File C:\RRbackups\C\0\Data610 50003968 bytes
File C:\RRbackups\C\0\Data63 50003968 bytes
File C:\RRbackups\C\0\Data65 50003968 bytes
File C:\RRbackups\C\0\Data669 50003968 bytes
File C:\RRbackups\C\0\Data688 50003968 bytes
File C:\RRbackups\C\0\Data706 50003968 bytes
File C:\RRbackups\C\0\Data725 50003968 bytes
File C:\RRbackups\C\0\Data744 50003968 bytes
File C:\RRbackups\C\0\Data763 50003968 bytes
File C:\RRbackups\C\0\Data782 50003968 bytes
File C:\RRbackups\C\0\Data800 50003968 bytes
File C:\RRbackups\C\0\Data82 50003968 bytes
File C:\RRbackups\C\0\Data84 50003968 bytes
File C:\RRbackups\C\0\Data859 50003968 bytes
File C:\RRbackups\C\0\Data878 50003968 bytes
File C:\RRbackups\C\0\Data897 50003968 bytes
File C:\RRbackups\C\0\Data915 50003968 bytes
File C:\RRbackups\C\0\Data934 50003968 bytes
File C:\RRbackups\C\0\Data953 50003968 bytes
File C:\RRbackups\C\0\Data972 50003968 bytes
File C:\RRbackups\C\0\Data86 50003968 bytes
File C:\RRbackups\C\0\Data860 50003968 bytes
File C:\RRbackups\C\0\Data861 50003968 bytes
File C:\RRbackups\C\0\Data862 50003968 bytes
File C:\RRbackups\C\0\Data863 50003968 bytes
File C:\RRbackups\C\0\Data864 50003968 bytes
File C:\RRbackups\C\0\Data865 50003968 bytes
File C:\RRbackups\C\0\Data866 50003968 bytes
File C:\RRbackups\C\0\Data867 50003968 bytes
File C:\RRbackups\C\0\Data868 50003968 bytes
File C:\RRbackups\C\0\Data869 50003968 bytes
File C:\RRbackups\C\0\Data87 50003968 bytes
File C:\RRbackups\C\0\Data870 50003968 bytes
File C:\RRbackups\C\0\Data871 50003968 bytes
File C:\RRbackups\C\0\Data872 50003968 bytes
File C:\RRbackups\C\0\Data873 50003968 bytes
File C:\RRbackups\C\0\Data874 50003968 bytes
File C:\RRbackups\C\0\Data875 50003968 bytes
File C:\RRbackups\C\0\Data876 50003968 bytes
File C:\RRbackups\C\0\Data877 50003968 bytes
File C:\RRbackups\C\0\Data879 50003968 bytes
File C:\RRbackups\C\0\Data88 50003968 bytes
File C:\RRbackups\C\0\Data880 50003968 bytes
File C:\RRbackups\C\0\Data881 50003968 bytes
File C:\RRbackups\C\0\Data882 50003968 bytes
File C:\RRbackups\C\0\Data883 50003968 bytes
File C:\RRbackups\C\0\Data884 50003968 bytes
File C:\RRbackups\C\0\Data885 50003968 bytes
File C:\RRbackups\C\0\Data886 50003968 bytes
File C:\RRbackups\C\0\Data887 50003968 bytes
File C:\RRbackups\C\0\Data888 50003968 bytes
File C:\RRbackups\C\0\Data889 50003968 bytes
File C:\RRbackups\C\0\Data89 50003968 bytes
File C:\RRbackups\C\0\Data890 50003968 bytes
File C:\RRbackups\C\0\Data891 50003968 bytes
File C:\RRbackups\C\0\Data892 50003968 bytes
File C:\RRbackups\C\0\Data893 50003968 bytes
File C:\RRbackups\C\0\Data894 50003968 bytes
File C:\RRbackups\C\0\Data895 50003968 bytes
File C:\RRbackups\C\0\Data896 50003968 bytes
File C:\RRbackups\C\0\Data898 50003968 bytes
File C:\RRbackups\C\0\Data899 50003968 bytes
File C:\RRbackups\C\0\Data9 50003968 bytes
File C:\RRbackups\C\0\Data90 50003968 bytes
File C:\RRbackups\C\0\Data900 50003968 bytes
File C:\RRbackups\C\0\Data901 50003968 bytes
File C:\RRbackups\C\0\Data902 50003968 bytes
File C:\RRbackups\C\0\Data903 50003968 bytes
File C:\RRbackups\C\0\Data904 50003968 bytes
File C:\RRbackups\C\0\Data905 50003968 bytes
File C:\RRbackups\C\0\Data906 50003968 bytes
File C:\RRbackups\C\0\Data907 50003968 bytes
File C:\RRbackups\C\0\Data908 50003968 bytes
File C:\RRbackups\C\0\Data909 50003968 bytes
File C:\RRbackups\C\0\Data91 50003968 bytes
File C:\RRbackups\C\0\Data910 50003968 bytes
File C:\RRbackups\C\0\Data911 50003968 bytes
File C:\RRbackups\C\0\Data912 50003968 bytes
File C:\RRbackups\C\0\Data913 50003968 bytes
File C:\RRbackups\C\0\Data914 50003968 bytes
File C:\RRbackups\C\0\Data916 50003968 bytes
File C:\RRbackups\C\0\Data917 50003968 bytes
File C:\RRbackups\C\0\Data918 50003968 bytes
File C:\RRbackups\C\0\Data919 50003968 bytes
File C:\RRbackups\C\0\Data92 50003968 bytes
File C:\RRbackups\C\0\Data920 50003968 bytes
File C:\RRbackups\C\0\Data921 50003968 bytes
File C:\RRbackups\C\0\Data922 50003968 bytes
File C:\RRbackups\C\0\Data923 50003968 bytes
File C:\RRbackups\C\0\Data924 50003968 bytes
File C:\RRbackups\C\0\Data925 50003968 bytes
File C:\RRbackups\C\0\Data926 50003968 bytes
File C:\RRbackups\C\0\Data927 50003968 bytes
File C:\RRbackups\C\0\Data928 50003968 bytes
File C:\RRbackups\C\0\Data929 50003968 bytes
File C:\RRbackups\C\0\Data93 50003968 bytes
File C:\RRbackups\C\0\Data930 50003968 bytes
File C:\RRbackups\C\0\Data931 50003968 bytes
File C:\RRbackups\C\0\Data932 50003968 bytes
File C:\RRbackups\C\0\Data933 50003968 bytes
File C:\RRbackups\C\0\Data935 50003968 bytes
File C:\RRbackups\C\0\Data936 50003968 bytes
File C:\RRbackups\C\0\Data937 50003968 bytes
File C:\RRbackups\C\0\Data938 50003968 bytes
File C:\RRbackups\C\0\Data939 50003968 bytes
File C:\RRbackups\C\0\Data94 50003968 bytes
File C:\RRbackups\C\0\Data940 50003968 bytes
File C:\RRbackups\C\0\Data941 50003968 bytes
File C:\RRbackups\C\0\Data942 50003968 bytes
File C:\RRbackups\C\0\Data943 50003968 bytes
File C:\RRbackups\C\0\Data944 50003968 bytes
File C:\RRbackups\C\0\Data945 50003968 bytes
File C:\RRbackups\C\0\Data946 50003968 bytes
File C:\RRbackups\C\0\Data947 50003968 bytes
File C:\RRbackups\C\0\Data948 50003968 bytes
File C:\RRbackups\C\0\Data949 50003968 bytes
File C:\RRbackups\C\0\Data95 50003968 bytes
File C:\RRbackups\C\0\Data950 50003968 bytes
File C:\RRbackups\C\0\Data951 50003968 bytes
File C:\RRbackups\C\0\Data952 50003968 bytes
File C:\RRbackups\C\0\Data954 50003968 bytes
File C:\RRbackups\C\0\Data955 50003968 bytes
File C:\RRbackups\C\0\Data956 50003968 bytes
File C:\RRbackups\C\0\Data957 50003968 bytes
File C:\RRbackups\C\0\Data958 50003968 bytes
File C:\RRbackups\C\0\Data959 50003968 bytes
File C:\RRbackups\C\0\Data96 50003968 bytes
File C:\RRbackups\C\0\Data960 50003968 bytes
File C:\RRbackups\C\0\Data961 50003968 bytes
File C:\RRbackups\C\0\Data962 50003968 bytes
File C:\RRbackups\C\0\Data963 50003968 bytes
File C:\RRbackups\C\0\Data964 50003968 bytes
File C:\RRbackups\C\0\Data965 50003968 bytes
File C:\RRbackups\C\0\Data966 50003968 bytes
File C:\RRbackups\C\0\Data967 50003968 bytes
File C:\RRbackups\C\0\Data968 50003968 bytes
File C:\RRbackups\C\0\Data969 50003968 bytes
File C:\RRbackups\C\0\Data97 50003968 bytes
File C:\RRbackups\C\0\Data970 50003968 bytes
File C:\RRbackups\C\0\Data971 50003968 bytes
File C:\RRbackups\C\0\Data973 50003968 bytes
File C:\RRbackups\C\0\Data974 50003968 bytes
File C:\RRbackups\C\0\Data975 50003968 bytes
File C:\RRbackups\C\0\Data976 50003968 bytes
File C:\RRbackups\C\0\Data977 50003968 bytes
File C:\RRbackups\C\0\Data978 50003968 bytes
File C:\RRbackups\C\0\Data979 50003968 bytes
File C:\RRbackups\C\0\Data98 50003968 bytes
File C:\RRbackups\C\0\Data980 50003968 bytes
File C:\RRbackups\C\0\Data981 50003968 bytes
File C:\RRbackups\C\0\Data982 50003968 bytes
File C:\RRbackups\C\0\Data983 50003968 bytes
File C:\RRbackups\C\0\Data984 50003968 bytes
File C:\RRbackups\C\0\Data985 50003968 bytes
File C:\RRbackups\C\0\Data986 50003968 bytes
File C:\RRbackups\C\0\Data987 50003968 bytes
File C:\RRbackups\C\0\Data988 50003968 bytes
File C:\RRbackups\C\0\Data989 50003968 bytes
File C:\RRbackups\C\0\Data99 50003968 bytes
File C:\RRbackups\C\0\Data990 50003968 bytes
File C:\RRbackups\C\0\Data991 50003968 bytes
File C:\RRbackups\C\0\Data992 50003968 bytes
File C:\RRbackups\C\0\Data993 50003968 bytes
File C:\RRbackups\C\0\Data994 50003968 bytes
File C:\RRbackups\C\0\Data995 50003968 bytes
File C:\RRbackups\C\0\Data996 50003968 bytes
File C:\RRbackups\C\0\Data997 50003968 bytes
File C:\RRbackups\C\0\Data998 50003968 bytes
File C:\RRbackups\C\0\Data999 50003968 bytes
File C:\RRbackups\C\0\dats 0 bytes
File C:\RRbackups\C\0\EFSFile 0 bytes
File C:\RRbackups\C\0\HashFile 1912506 bytes
File C:\RRbackups\C\0\Info 756 bytes
File C:\RRbackups\C\0\TOCFile 194438110 bytes
File C:\RRbackups\C\1 0 bytes
File C:\RRbackups\C\1\Data27 50003968 bytes
File C:\RRbackups\C\1\Data46 50003968 bytes
File C:\RRbackups\C\1\Data65 50003968 bytes
File C:\RRbackups\C\1\Data84 50003968 bytes
File C:\RRbackups\C\1\Data0 50003968 bytes
File C:\RRbackups\C\1\Data1 50003968 bytes
File C:\RRbackups\C\1\Data10 50003968 bytes
File C:\RRbackups\C\1\Data100 50003968 bytes
File C:\RRbackups\C\1\Data101 50003968 bytes
File C:\RRbackups\C\1\Data102 50003968 bytes
File C:\RRbackups\C\1\Data103 50003968 bytes
File C:\RRbackups\C\1\Data104 50003968 bytes
File C:\RRbackups\C\1\Data105 26728315 bytes
File C:\RRbackups\C\1\Data11 50003968 bytes
File C:\RRbackups\C\1\Data12 50003968 bytes
File C:\RRbackups\C\1\Data13 50003968 bytes
File C:\RRbackups\C\1\Data14 50003968 bytes
File C:\RRbackups\C\1\Data15 50003968 bytes
File C:\RRbackups\C\1\Data16 50003968 bytes
File C:\RRbackups\C\1\Data17 50003968 bytes
File C:\RRbackups\C\1\Data18 50003968 bytes
File C:\RRbackups\C\1\Data19 50003968 bytes
File C:\RRbackups\C\1\Data2 50003968 bytes
File C:\RRbackups\C\1\Data20 50003968 bytes
File C:\RRbackups\C\1\Data21 50003968 bytes
File C:\RRbackups\C\1\Data22 50003968 bytes
File C:\RRbackups\C\1\Data23 50003968 bytes
File C:\RRbackups\C\1\Data24 50003968 bytes
File C:\RRbackups\C\1\Data25 50003968 bytes
File C:\RRbackups\C\1\Data26 50003968 bytes
File C:\RRbackups\C\1\Data28 50003968 bytes
File C:\RRbackups\C\1\Data29 50003968 bytes
File C:\RRbackups\C\1\Data3 50003968 bytes
File C:\RRbackups\C\1\Data30 50003968 bytes
File C:\RRbackups\C\1\Data31 50003968 bytes
File C:\RRbackups\C\1\Data32 50003968 bytes
File C:\RRbackups\C\1\Data33 50003968 bytes
File C:\RRbackups\C\1\Data34 50003968 bytes
File C:\RRbackups\C\1\Data35 50003968 bytes
File C:\RRbackups\C\1\Data36 50003968 bytes
File C:\RRbackups\C\1\Data37 50003968 bytes
File C:\RRbackups\C\1\Data38 50003968 bytes
File C:\RRbackups\C\1\Data39 50003968 bytes
File C:\RRbackups\C\1\Data4 50003968 bytes
File C:\RRbackups\C\1\Data40 50003968 bytes
File C:\RRbackups\C\1\Data41 50003968 bytes
File C:\RRbackups\C\1\Data42 50003968 bytes
File C:\RRbackups\C\1\Data43 50003968 bytes
File C:\RRbackups\C\1\Data44 50003968 bytes
File C:\RRbackups\C\1\Data45 50003968 bytes
File C:\RRbackups\C\1\Data47 50003968 bytes
File C:\RRbackups\C\1\Data48 50003968 bytes
File C:\RRbackups\C\1\Data49 50003968 bytes
File C:\RRbackups\C\1\Data5 50003968 bytes
File C:\RRbackups\C\1\Data50 50003968 bytes
File C:\RRbackups\C\1\Data51 50003968 bytes
File C:\RRbackups\C\1\Data52 50003968 bytes
File C:\RRbackups\C\1\Data53 50003968 bytes
File C:\RRbackups\C\1\Data54 50003968 bytes
File C:\RRbackups\C\1\Data55 50003968 bytes
File C:\RRbackups\C\1\Data56 50003968 bytes
File C:\RRbackups\C\1\Data57 50003968 bytes
File C:\RRbackups\C\1\Data58 50003968 bytes
File C:\RRbackups\C\1\Data59 50003968 bytes
File C:\RRbackups\C\1\Data6 50003968 bytes
File C:\RRbackups\C\1\Data60 50003968 bytes
File C:\RRbackups\C\1\Data61 50003968 bytes
File C:\RRbackups\C\1\Data62 50003968 bytes
File C:\RRbackups\C\1\Data63 50003968 bytes
File C:\RRbackups\C\1\Data64 50003968 bytes
File C:\RRbackups\C\1\Data66 50003968 bytes
File C:\RRbackups\C\1\Data67 50003968 bytes
File C:\RRbackups\C\1\Data68 50003968 bytes
File C:\RRbackups\C\1\Data69 50003968 bytes
File C:\RRbackups\C\1\Data7 50003968 bytes
File C:\RRbackups\C\1\Data70 50003968 bytes
File C:\RRbackups\C\1\Data71 50003968 bytes
File C:\RRbackups\C\1\Data72 50003968 bytes
File C:\RRbackups\C\1\Data73 50003968 bytes
File C:\RRbackups\C\1\Data74 50003968 bytes
File C:\RRbackups\C\1\Data75 50003968 bytes
File C:\RRbackups\C\1\Data76 50003968 bytes
File C:\RRbackups\C\1\Data77 50003968 bytes
File C:\RRbackups\C\1\Data78 50003968 bytes
File C:\RRbackups\C\1\Data79 50003968 bytes
File C:\RRbackups\C\1\Data8 50003968 bytes
File C:\RRbackups\C\1\Data80 50003968 bytes
File C:\RRbackups\C\1\Data81 50003968 bytes
File C:\RRbackups\C\1\Data82 50003968 bytes
File C:\RRbackups\C\1\Data83 50003968 bytes
File C:\RRbackups\C\1\Data85 50003968 bytes
File C:\RRbackups\C\1\Data86 50003968 bytes
File C:\RRbackups\C\1\Data87 50003968 bytes
File C:\RRbackups\C\1\Data88 50003968 bytes
File C:\RRbackups\C\1\Data89 50003968 bytes
File C:\RRbackups\C\1\Data9 50003968 bytes
File C:\RRbackups\C\1\Data90 50003968 bytes
File C:\RRbackups\C\1\Data91 50003968 bytes
File C:\RRbackups\C\1\Data92 50003968 bytes
File C:\RRbackups\C\1\Data93 50003968 bytes
File C:\RRbackups\C\1\Data94 50003968 bytes
File C:\RRbackups\C\1\Data95 50003968 bytes
File C:\RRbackups\C\1\Data96 50003968 bytes
File C:\RRbackups\C\1\Data97 50003968 bytes
File C:\RRbackups\C\1\Data98 50003968 bytes
File C:\RRbackups\C\1\Data99 50003968 bytes
File C:\RRbackups\C\1\dats 0 bytes
File C:\RRbackups\C\1\EFSFile 0 bytes
File C:\RRbackups\C\1\HashFile 1979082 bytes
File C:\RRbackups\C\1\Info 756 bytes
File C:\RRbackups\C\1\TOCFile 201206670 bytes
File C:\RRbackups\common 0 bytes
File C:\RRbackups\common\backups.dat 8192 bytes
File C:\RRbackups\common\bmgrmode.dat 29 bytes
File C:\RRbackups\common\bt0.dat 32256 bytes
File C:\RRbackups\common\bt1.dat 32256 bytes
File C:\RRbackups\common\css.dat 8192 bytes
File C:\RRbackups\common\hints.dat 8192 bytes
File C:\RRbackups\common\mnd.dat 8192 bytes
File C:\RRbackups\common\regcerts.dat 8192 bytes
File C:\RRbackups\common\restore.log 110 bytes
File C:\RRbackups\common\rr.log 94046 bytes
File C:\RRbackups\common\rr_bcdenum.dat 4168 bytes
File C:\RRbackups\common\SAM 262144 bytes
File C:\RRbackups\common\secpolicy.dat 20480 bytes
File C:\RRbackups\common\settings.dat 32768 bytes
File C:\RRbackups\common\system.dat 12288 bytes
File C:\RRbackups\common\tvtcmn.dat 8192 bytes
File C:\RRbackups\common\tvtns.bin 23 bytes
File C:\RRbackups\common\usersids.dat 20800 bytes
File C:\RRbackups\Documents and Settings 0 bytes
File C:\RRbackups\Documents and Settings\Administrator 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\C rypto 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\C rypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\C rypto\RSA\S-1-5-21-432148126-3170665589-795329589-500 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\C rypto\RSA\S-1-5-21-432148126-3170665589-795329589-500\8f71098770f72c7a67cd8f1151619865_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 54 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\P rotect 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\P rotect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\P rotect\S-1-5-21-2954931239-385123427-3653054573-500 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\P rotect\S-1-5-21-2954931239-385123427-3653054573-500\3a1b7501-4387-496f-a860-64554f41ab50 388 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\P rotect\S-1-5-21-2954931239-385123427-3653054573-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\P rotect\S-1-5-21-432148126-3170665589-795329589-500 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\P rotect\S-1-5-21-432148126-3170665589-795329589-500\a9d39b00-924f-4c0c-853b-5f7fcb676fad 388 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\P rotect\S-1-5-21-432148126-3170665589-795329589-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\S ystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\S ystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\S ystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\S ystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\AppData\Roaming\Microsoft\S ystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\lqi 0 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData 0 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming 0 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Lenovo\Client Security Solution 0 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Lenovo\Client Security Solution\enroll.ini 32 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Lenovo\Client Security Solution\hibernation.dat 4 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA\ S-1-5-21-432148126-3170665589-795329589-1003 0 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA\ S-1-5-21-432148126-3170665589-795329589-1003\340c8499eaf8cbb14bea44864100070c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1332 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA\ S-1-5-21-432148126-3170665589-795329589-1003\62a45886e06c7d046ea8b819bec0598a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 45 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA\ S-1-5-21-432148126-3170665589-795329589-1003\6b29ae44e85efac3c72ff4d1865d73f1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 53 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA\ S-1-5-21-432148126-3170665589-795329589-1003\7d8bfe4931d42bc369eef7d8b6f1b4c9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1332 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA\ S-1-5-21-432148126-3170665589-795329589-1003\7fa9c2d66826f040a06f48e635c17041_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1332 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA\ S-1-5-21-432148126-3170665589-795329589-1003\83aa4cc77f591dfc2374580bbd95f6ba_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 45 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA\ S-1-5-21-432148126-3170665589-795329589-1003\8f71098770f72c7a67cd8f1151619865_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 54 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Crypto\RSA\ S-1-5-21-432148126-3170665589-795329589-1003\ad26b2bffb3e99f6133cb56b56a0014d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1332 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\CRE DHIST 24 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003 0 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003\2497295e-a6ff-4d9b-8c3c-b846023f3cb0 388 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003\35d352e9-6cec-4708-9ebd-37785d7ff08d 388 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003\4c311c10-8d5f-412d-b0a6-67c7e7628e78 388 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003\64c343be-675b-4ff6-a575-45165fa27677 388 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003\8ad852a9-1a5b-45f0-b554-1ef9e31db8f8 388 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003\a55e2e77-34b6-4433-ba52-8785b77ed22c 388 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003\d487cdff-bf61-46b0-b6a1-aad5b2587fdd 388 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003\fdc614d8-6bc1-41b6-a91d-2c543e672e05 388 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\Protect\S-1-5-21-432148126-3170665589-795329589-1003\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\SystemCerti ficates 0 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\SystemCerti ficates\My 0 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\SystemCerti ficates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\SystemCerti ficates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\lqi\AppData\Roaming\Microsoft\SystemCerti ficates\My\CTLs 0 bytes
File C:\RRbackups\ProgramData 0 bytes
File C:\RRbackups\ProgramData\Microsoft 0 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto 0 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys 0 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\02dfef17062ef2431843d47ec606106b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\04836675d4aef5970c10786062c1ef4f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\051b13e309d8e929368f0f184e1cd6b9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\0bb6bf26f4b4223cf2ce5f15320258f1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\0fd79e0df429ed8b6ad56d35e97900bc_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\135128de7da34765902b3ac2a15b53fb_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\228b3307ee120960fa7bc981f11b07f1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\29e82af4afc767035851101cbb096093_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\2c2a3076aa9452873d11869b5b82545d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\35461bc1efa0e88721435b76a1458417_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\3d44ba49e15c263e23fc9f25f98df788_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\3dd558fa5de4219da717374594e58574_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\3e9fd40d700297ec091a0a2abeffc896_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\3f9d8f0cb42f7952b1d1aa5400d3f029_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\43d1049338eb06a6f576124429028959_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\45a8a926ee21a614cbd7fe632749dd40_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\492932733e5be048e4eb5316d2915bfa_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\4b743ca12f2bd13d0989f560a44e2c55_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\4e644aa26d4668a647d9dc62c9c98b46_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\5a24e495f22d6c1ef0a82e7782d4a8a9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\5dbc6d95b2ff47a533806688fd34117d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\5fd02a6b23562662a6cb0e471dfa39f9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\63a0d44b192eab6dadb84b75f2149f50_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\6617fb65cc2e63c6c4d7f324a51726e6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\1d10613f2ee966c84d6d08e3bb10dc13_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\4e59c873f40923ce700185cae19e8d67_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\77c6ac1113d8c12d29510857cf24887c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\a0876bf21bd2d3fc57718d1034b04f7d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\cb5711b693fca91e6716249549874fd1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\6c680727dfac19a9df999734358e32e7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\71515343ba2ad84049670f95b92dbcc6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\72b12c26eddb5887ac5c650b877d69e2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\731b1e3b8827140b2437f7d2d364abad_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\73a0a4df93e55407c2ab582ab0d31534_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\75dc40c0bd44c4b6c8d9233839b82cce_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\7850cd832470564bb798447238d0f5a1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\7b214f26ea27b34de34b1caa21dac2b5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\7c36cc5eab650472ee31eb657950667e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\7d21f082ba5d6d1ab71cc19a74620fc8_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\7e6e9ddfcafb8126cc0e8389b15f5bdc_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\8282e8491eefafb505a6708815b870ac_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\85c29698354827f41950a6dd5d34dc36_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\8a50cac3f80ee2626f1af95ecf128b1e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\8ccc8eafa87a08489b235008a203ab68_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\94d55ff7df0770e758efc28974ca9b02_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\956ad10d58b113cb1fcaa6fdc9e12fbc_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\9de385a8cc241d241afa81103f4e3352_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\a1078b3a38a3db2fa971e00633c1e270_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\a9fea6c2b04ea01f95420fba2de317c4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\abc682d080ba323b7405de263ceedd61_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\ae5401eb2f82750f5f7b56389f6a2000_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\af613da282cd4b826ef8caa1a1f97f1c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\b25d710d6334a5500bd8e9f06016e3a4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\b82b69ef84927f9e283532c1b7f98e75_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\ba725f5e778faf6b8202241e8efaddb2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\bce825ba9f2c21c73598fcdb672ca32e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\bdf7b3761c6f7bdf4a2f5bbfa48dd1ea_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\c5a6327b3caef2bf2f1512aa3a658107_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\cad22f0cfb08f5ee78d507cfaddcd175_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\d2bd7e426526cf89736dbd99f7230c93_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\d5f31bab4b933e26ecfec30c9a2578e6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\d8485f09a481470433d5ea96ac7440c3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\d881cbbb913ddb4f4b0065f4a0ad7a77_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\e20ecd0f5458e729de49a695df2fad94_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\e21c346bfa45211cb639e6748de64787_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\e25f18cba290c1e7e3b595f8adb4a6b7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\e325bc14d087a2dd00047475d2ea6f0b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\e555bd8697dbb94d37e99032802a5e94_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\e60c399420b4bc2eb668c2ec82e9dc42_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\eb9b8498fafe1a064500d02b9031328a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\eede0f6f2e71e48731f0bdccc694d9a7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\f37a42650f2ec4427531b83ffbac45ea_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\f63e1a83ad35d2d00499eb47c50927cf_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1305 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\fc1e3851f429ea606d6ff1e01a5229f1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 52 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\Mach ineKeys\fcad562231fd1169ef17d25fb9b1e154_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 77 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18 0 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\000b42e96d09afcdf63d3ddf543246b4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\00d9c42b52d204bc9aa112a82ddf7d39_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\00f38c23dafbcff664ed55c0d5206983_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\018b6eae123be07930b1128fad75e780_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0209427ab6eb2d12ed27dfb320aaa5f0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\028697626d931a3dadc2af27b1e29acb_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0386f043889bced0a68ebdd17e9c5a60_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\050c6b37b2a158c4d2fb908e65d99528_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\05ca45fd6d214ab9cf6a79f31309adfb_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0666c7c4431bf9597875e21872f9c850_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\082b89ba8486c0f32fd0eb0bdce06212_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\093406d23d3cda8c7a3ebe14ec51913f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0954cc647aca7d7d0e3b6a03bc919d51_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\098cfcc3485f74920393e9633a10f454_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\098f9c85ac85b3eb42b387b3cd6679fc_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\09d605c30e84a6393735e17a1f08ce52_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0a9ffbad1919393e593226a004127cd5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0bba4d23d287958d284dbae55c80a441_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0d6557f64385315df2bf8b51e41f0797_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0dc84f417cd79202bb417e97e511cbc1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0fa6d93d9415ad519adfd09234df557f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\112c5b94a205c885c0a3de671942bced_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1142d7aeaf4242033dd6085c8fb95236_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\115b7df1cbda80fe5ee4582a96b2086d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\02a29626fdd2b823d50324a0bc7939e3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\0c65988d028b34539afec61b47edbba5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\142f9c0033f01fd627ff92786e240208_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1eee79fd85bb2a840645baba93f5a9dd_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\2745a9efbfbc8778e5006c6eda693bc8_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\310d393fbe9ae7ea4ee053478529a1d0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\119c1a377c8c62dc17b066f7251e0e86_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\11a2b062bc4be91f18bc1eb4f88518b7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1270ce1b789d584cbb1b9f847ac98d37_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\12eb9eff6e6b88eac03d4d4823f47b42_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\12fd4459348c47cc2c5b685b6d2105d7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1386e232fe50cbfeecfd2c81201c45a3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\152e29cd616437519c2221999497e68d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\155907eb654d9d3c9153d612d30241c6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\16403542cc9738c9946dd123cdf9e444_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1671cf1ac4275f43e312731122c1fc4a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1778eef9b421ce15d5566b44165a7979_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1838e04e6a4ce49a3118821cc969f3c7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1c5bf14ebe4991762fbd7bdde1bb153a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1d19d12b3fd49ec72904b6d7b027512b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1d694700c39e6a53f96ff972071ac607_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1df755c48a017770dc73c91523b8420d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1e369f56f9718a6ae35dec3abf5cb87b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1eac9c7f0df32862cf64a3f111d440ff_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\1f7d892a6f9f81b2cbe8ad1a5db815dc_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\20087edeca749928d68c58fd2fb068e0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\21891995768b98f68c7655e054721c94_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\21e5cc130b7e10a0cb08b8aebebc36ea_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\227c4d2ed9f80484844cc88efc526d27_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\22840d626ca167a282f9b65a80775a0f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\2428e4ce85eadbdccdb27e5144b59510_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\242bbd42d7facbc3ae0ed1a423d9bae0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\24404e275d016b6745775c22227f4feb_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\24bc456f3b0fbd2e3090c5ea25767a9d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\263c1c20f70bee47f2f6e5d534ec00d8_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\273b6f8050d735370e2875324d152efc_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\2748d0ae1fff633bd2376af401e45b32_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\277f1e66b46bbdd68f425e9da0f6d16f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\29bf7b94312dc8b2efdac53345839a4a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\2abe9ecde293901f959c1698a2ee19f2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\2b55b4475275fe3f3739db22ca702013_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\2c196ffa1849498eb9fbb319706e78a3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\2c8c25a510cbdb1e90074ea1823396cb_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\2d02686a8c1ca4025c074672b85db174_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\2de994560af9ecab4520a2ec70550ec0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\3003816724d35e6e6657d8ce766eee8d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\309029022f23b5754f3b3c2bf15b5bba_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\30cddbd8b39674d1be1660e65feb666b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\31297b2a8c2acd7854df801655e981f5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\31f96ca0f6ebc9981256c8cc2459572a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\323546e6d8c82323da7a636e22cf5dc8_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\324e0566f68ac9b5d8b05771c26b6855_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\326518c4e053a6ea5ae4d389809e5bbd_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\32cb42f24a14bf0f8632ef6b22621106_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\32e8b97e00bf2b93f041c9f3ffa1db14_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\3341a48e433100de9250c38dde860338_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\336098a78bce9fa7865e324d5b425f26_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\33cb7a313a40944ed2684c65fcda2ae7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\34eb1f8f4eb73109436de2f8b91b6395_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\34ee69d729fcfbf7c4aad5a261a6686e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\35bea52f922727a4159b2b96d450b65c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\36155407510fbc7e5836de7e3cdce6e1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\3627da60426c85d1da15c83b2c39c1b5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\368e1ec10e3c7b5fdd90f949d121b2c9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\3749a38d8a55d7dd0b347ef40c4bf4fd_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\3848be85452c3a4e7a7aa633fc1143a5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\3868841b997c5eb8242c78ebcb5f63b0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\386f35104c678ee63ac2b7dbed54c20e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\38e8c918caa57d53579d22268d8d4ee1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\3d15a589ad55b0d44230cc7d1e89be71_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\3f6a91f8a896ec54865308eb7bec028d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\3f97b5bcf7ad655fc5bad6949e049eb2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\41deb19743a0ad411c86d8eaf4dbfb99_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\42240d2a03366a4ca99783b39770153f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\47996d66959160b273e09bea95de4f03_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4821220ae064352faac130986c82ff0d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4a72384ed9dea6a7e1ead23a5109bef2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4a76f9303c909ac3fe5151ad549c082a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4b82ba3534bbfee2e1296c9dbd75f1ef_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4c324a4cf1394c4bb90ce110b83e50c0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4c94ca07b3bf1742d4c26ed85857826c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4cc480b272c4a58827f926ae074f7cc3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4d2af19653231498786e4ec27d26b67d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4f7c21a2efb3f8e694d673081aca5590_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\517cbca02a6d17e2a203274de665e499_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\53418e1e88e93e1b4234f2ff210ebfb0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\53db1aa8b1eaa59aaff0e568ea3baac0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\54307fd1d0ac00760ce4cba470c263d7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\55942328870c0633cb4b13287da3dc6c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\55ce2df15d5c487f6345b6b9b50329e7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\56dd03c2ce5e81f3d873461af0ab211f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5791956828074a0df01278ef64e3f281_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\57ea8f6d5747434db8e7a6bc939a4b79_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\583569b1360201c08b22368b754bc098_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5964bb2b02ea929d3d1232d63b051cf8_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5b68c8c3bfeff58f7b2a3c9abab8db12_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5dd5b2fa27061ed54804a04460349f7b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5e0758e859e380783866a2931fcdd95b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5e665554ed3bdc7dee5924b91bcde4a7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5f07798e2aab8e3c8c1bc4160049d428_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5f5cb973c7b89f647e72e17ae5efbf2a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\60048ab75e065db838cd39e0fc376965_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\607e8a484ab179b0e4c5764eb20f9de6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\60c10df832cd4ae00799c1b9fa7657a5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\618e2d7188eb816440ba4a1f7cc880ac_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\61a32a677a5e5569e5e6ba5c61835514_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\61a4ab2993b52a2a5904f26e3ebb8ae5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\6210a2414d2091811319bf850edcea35_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\62a45886e06c7d046ea8b819bec0598a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 45 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\62e39a9950fdab4e0e0d71d52949f5f4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\63de350d0217113cc5c7a66ea928b067_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\66f8e2468ed3cdc46ae0bf84f7c0500b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\673bbf4059b305b1fccf0fdbca2cdb4f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\676d49c362d5cb5cf44a7fc0ccc2fa29_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\68e9a1816f851cc7dc063aa9f17fd0b0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\6921ad06af26197b9dcc52c89f7ef6b1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\6b25dae14f51b83632b0a16c395bbbba_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\6be60fd3b37facae250dbc86b9f17eb9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\6c472b80d3cc4f92be88601df57b93ac_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\6d14e4b1d8ca773bab785d1be032546e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 47 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\6fedf6e5691efe857a31478ea5d2006d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\70e3e680e7df39601cdd3af700934f42_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7271f84a2d63acfd4247fb7206371385_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\72c8fb553e2d59dfc8b4f22d614c8750_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\73181c2501d01b3dcded3405328321a2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7442508981b436956b297583f6c54104_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\35409e3509f790b5fadacc5ef0dafbda_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\410fa1ec8a666a1acc59b0b8195027da_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\4fde83c7e1f3774fdcea5e18ee13975a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\5bb3b524e410f40453fd4537642a34a9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\622dfe861d87906e5a3d0acdcf9716d1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\6e991195cbf4c6fcc1cea2bea01174b1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\754a7280f4f33ec3bfbb6899a5de36c0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\75b703602d0d152a6b97d51cd472c348_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\76f54eeda0b152e767e446027742a113_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\77e50834f4b00e67609bcb9c0fd526d1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\78628be7916dfbbdcc4e0755b76a814e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\78dc6182a2fd3e1b4956cf18875ebbc1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7ae641024b3d0bcc4b25a31eaa174550_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7b4746750dee66d89a3ff1bf3063521f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7c2e8f5c2ef6f7da584601a0ac72ce7f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7c7fc130d9872e763955ad63559890c6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7cd9b145fd045e6cbc0e65bc4f62ef55_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7d134b512886819e69d23bc3e9a964a4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7d75a3982955b5ff3a6abd013c039f19_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7d7a8edf24e25b9b5afd278fe71f2466_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7db3a3a2ee4d6ce11f354f93494e25a9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7f609d23740663427a323693f88bd10d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7fa6de15d04e5d07befba89a4a12dedd_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7ff109e75653c7956cc4741c310ab1a6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\800e2c151b0af10abfb4451d5987d6c8_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\802d0e794db81f3e4be8ff0899c9c4b0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\81cbb2f85f6ed804e43b788ab06eaba4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\82170cbad6529806a9352431f42ed9a1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\82171d8eace2505c0da54664f592b2fa_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\82a75891fc4cbe5e173edb0e1098f8e4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8308017948f132c015963d4848e0d76f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\831a5d62d735c94cd2b50c5a058637b2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8442e918db0036e9f0dc233afcaeed92_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\85438726335fad46e4e27771f4f7d363_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8619a015b39829ffcceda5f1e9aacd81_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\864dfad64f23e0240a80b522c38fe7e5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\86d221d33b613e913c9dc6b259fb4cc9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\88a11b4142e1516280560f62a76ce5b2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\89b900c5d9a257fff8b661db7ad32e28_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8bf67c07d431b3e7e14804147d59b7a5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8d76241491a347c9731943e005dcdaf1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8dea36f7790878ce2320fe319e269619_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8f2f8e071e3a627d9b876fa3a48b0e1a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8f6898c1007b80dd05ba823ec75ffa85_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8f71098770f72c7a67cd8f1151619865_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 54 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9054cdf08330aab4c53d1580be1bcfe4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\909f699f6c266c2f7f1d23ab41059a61_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9127c0f580daeca87fc6e3088defabb6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\92a92823dde9dba165a12885a10805c4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\92ca902f06122bf3972873fcf4d0510d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\93f136b11dc7b7c40e3576c93f2f4d9c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\94e1b64d9e83f84448c257c10e2dbd78_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\95f3dff7c85bcbe05c66c19a4ccddf3b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9613c157a5f9105e91202e4ab893e044_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9624deaec1435a8ce0207e6b83dcbebb_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\973d85211269d6add6811f49b572de26_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\97dc356cebb7d61ecbcc448e011ce66e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\98b8acaaf9a2c4883265bb29ecadb378_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9996e98d7a8e464e646143da8fb84ab9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\99f8e41d668570d54f218c7d6675267a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9a09831ce313be5d62c7c9e736e7b8fa_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9a7607c8d83dcba84febe1160e8d0a8f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9c7da449af14610d30d2a4a52f5de330_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9d1b5047917f55f5261a8700d19d8d86_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9d67d9d613d73e1754fe120a08408ce6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9db949848b281d93eba463a10feb9c24_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9f536178c7400d4b34992fd8b88d78f9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9fd8f5fb3b655a60c17917734c8d928a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a1d14fbb44823018be7294589764861e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a1e8be95995b7b506e0c41dbf0f2b908_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a242fc602d4a79168bd5a655b45934e1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a2b27787f8dddd4f9908e35d692b1278_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a46d6fa91383bbc4710b0b03322a2f69_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a4f58f9a2617e58b971fede3136501c2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a572bf78501da9e62b484d5d744e15d1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a65bd8fd48ee250be39bbf000ab83359_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a6a7ab7493edd04f791c508073fe9472_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a7bb025e7e88562b6a9cb330e89a01c2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\7a24c8c0c41ac33edae57ad435963eec_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\8003601468a500cd9af7b20b6f1ceeb2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\86627ba866fd95c7f29ebae9b6c06c72_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\926d3c1298401b9945fb5d0dd29dec21_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\9a020c1bff517c624aa0cb7c6feff820_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a2f326ca9addef08a9b49cd0468051e7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a7e35ea92f17613eb2b2e373528336bc_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a89caceca2bdcd1d32e606e90a63a12e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a9140c85ff9365106e6a45e709bd6f5c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\a9761fd0be0d6e2200d9bc62c0a542e0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ab475b4f414a8270ac0522578f64857f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ab4ba518864bf960fb3244cdf7bc78e7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\abb399d10d081e77225aa814a087f65c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\abe8ed6ea68ab66e8301e480ebec335e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ac8a62a55f0142c8457d001b4a27aef9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ad32e75ae845baa0ee84aa6d422f2348_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\addf9c663866a310fcba8a29d2f80044_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ae32a1a4943b05b60b24c4c48a490b85_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ae8cd8961b2eb77eca07ba04769f0135_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\af1786190a6e585eead084e2485e6f7d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b0a62b5a0f875106cc85b8c0d323de98_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b3cf837eca757760267cc645b183577f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b3fcd4e595f10ec5edf96ccbdbeb9d0f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b4d994cc08d854414c4f332b6db5d318_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b55984a1caacd751b0b10db2f4e61f4a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b59b036715e4140c8e4447c0f2fb506b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b5e9b51b5ed4cdaea6795c4615dad4de_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b7366252d951777693ea01ee8f6fdfbf_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b809f75a0bd3d606f301080e94c8fe0e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b8277775bffe44b38cad640491c1a7e8_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b8feeb0a18985b34eff6688738eeeb51_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b98a9214af4d70fe94701b6998d922d2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b9c348a4dd73ef365e52e4065a757356_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b9ef25a58499f49f44f7b86db16b18bf_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\bb55cb9bb33e12f1cf3a400672810326_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\bb6b36f04e0d26fe5824be5801b8db9b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\bec66dcabd34575bda1169a594a935f7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\bf97e6fdf064359203136ecbb48fbe37_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c0a9f328d94b9db2e228717de4933af3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c15cbda44d389f01fcdf54ee31b1a39c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c4562262b64a9f3ab49be753319d3bcf_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c54bbff0a6a284dee25f70b9ff039825_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c5d0a17959db97850c7f3b4a0b302df0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c6015c58c3e8f63ed31d3d83d39854ee_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c62c5796f7881468ae880ba583799275_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c65dd1d9978f9060dea73831435b3f55_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c6924f790726a20860bc7f8363dccdce_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c692a8e64d0434aff4aad1f457bf0833_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c78896bc0bee16ed759656f1c8669ca0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c8e59f84097c33b27609253b88a813ac_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ca8ca2565602d5f1e4769075ae44e72d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\cb70b7541e36cd528d85a731f1cbe3fc_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\cb9f9b40fb72dad63511722a3e1c7168_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\cbf082456d588da00882f8f81d3e446a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\cc44d267bdc8978a01cbaa9217438b6e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\cc9e55cb86a1edfc0bbe04a2befb3db3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ccb97d2046c0c810df9e040bf6f059f2_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\cd8ce6882f504e722f83748b5571271d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\cd9b7fda3142a8e2b2e4aea0f288cd44_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\cdf4b674754fb600510b3d3f3792b0a3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d03e3121affc0665d0bd7d1d4a65e254_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d099dfba6afac790387dd8a01345ab65_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d0bd18b33319d03661f67887844e3c72_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d1df9181d86252381c8b8af5a142dd7f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d210d259f449126992eaa206823aeeec_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d24a03bd4c548c1968158330faff50bd_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d3a373368a1d61a058f8d1ee373b85a9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d42cc0c3858a58db2db37658219e6400_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 893 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d47489a70d420616490432a3d0466fc0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d4c0731e54c079070eda2abc8ebd020c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d5838f77898c891d5ab819631d7afb0c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d5ba19e121c9e1a78e43ba6ad63c837b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d6bc46bafb559febe7d387618246d298_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d783d75aa702808e497586cf4e1c0b74_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d93775aff46bd1cabb5341e5fd82ae96_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d9cdd5651950f207c2298b3771b15f6f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d9d40168238137910d5c112ef8102c3c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dba12b32e34ec7f093b3f07945d58e2d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\aba4a653b496b31e9213fc66251a8479_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\b5201703cd875d2900fe876178f5768c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\bbfc9d1be506761f32a6f1d7832fd751_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\c6f2408596046621afb67d870886f08f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ce850911a3dda6033d0f448a5cbf874b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d622aaa084496e1d9d8a24f3c51eef60_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ddc7c1acc433a5c59ce665004321818d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e63a512aa71c0a063c2b8b8b64e7f156_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ee8cc76abdda94f65008180c58d57df6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f4772e6e0220c2a99798b4a59922b23f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dc0edc307b83eee946fb82aed15ebbac_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dc0ff57d540a9f03fa31d3ef841ae827_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dc20f685f59391a634ea8deba31a5834_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dc989cee0b6cf8bc65f67e8bfb1f921e_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dd1ae967c7b6a220fa38752e4e944537_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dd4aa37be44fffd9c3383b694465e3d4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\de1d0ebee9e9817b3556856acc8a2e3d_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dfc2fc442d7390ab3b14526b18238663_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dfc31b33a2eaf6705e59dabc2007dd43_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dfcf6c97f5a2a9592e557e3d597fb2c3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\dfd0edac581ca124caf8173a61926044_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e0e9ca9e1ceb0418cbd53ca3b5546551_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e1646849cd0c2a1ad8a1bb17b32ccf7c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e26a46937d2f0441900f33358144e951_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e31aa44acef5bf97169abb8eb1155b55_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e40e744eeefc169ccde265ead7516234_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e429a1d6d4edb17b47dbc4b43d6efc43_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e53dc4daccf861f6128271171b6a2136_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e664e66b745af030ca6fda67357645a6_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e68af571ac2e2410b9270468a9891a89_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e73fe0d2dd986438cc3eb28cde3694a4_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e7463a3bb96d57fd5a34980a810d75b7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e7ae638252d6919850c7bce950631954_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e8647b3b919f3da565627de8547d75c0_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\e8b14950129b0ead8cb50da25e655b7f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ea3aea13ed38c9db32b7fed800c91b59_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ec29ccf8bd5a7f21ae079aa907a9005a_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ec40bd9051ef9e84b07b88e54d4ba573_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ece571cd0be97825a68f10b6877376b7_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ed2e99041efd32114c6cc73b8a418f0f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\eefddf2d168e544f3d55379c3ebedd21_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ef34555207506dbb7b0cec334a940207_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ef4ef7cee2393128b9b81031eee809f8_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f08504f127c66de609e6b42a0a97c779_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f0c66157e861d31041f9b06c51492bd5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f20ac7eef155a17db4343296fe8d27e3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f2431d63bedb73609187892017372897_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f25234c2056f701bb2fa575fd83ce8c5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f2f5082895d618ed6fa3957bac9b1e06_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f353fc5ae8479d45452912011ea53bd5_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f432c76ebfb39c5f55bb2692d59af39f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f453d47eab12ce7017271e0b75b56ee3_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f4f268ff7c1e7adf9bc4bc242b7dc666_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f5a44cc5fef6c5f07eb0a8f957474ace_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f5bb1dc3f9cc4b23afba3d402afda7d9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f64fdbaabc358abb7fedb41ea1f2664f_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f75b965e8ec7c397d34e0deedc780ad9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f774a2ba20d18abc377b1998ab351224_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f784e87b779a983d0a33bb3b1ef8fa82_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\f8388c163e4b443b87ac2ed6481b76ee_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\fa0b82ac37abd5bd4dbd2e354901f412_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\fb91dede2cd63c277ee916147585d61b_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\fb93953756f285c2c4f4eb32569c60c1_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\fbe550c14a0d4a104a7d5e1e817cb130_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\fc7de783986de0c7075c1e0867fb9d01_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\fca20260c5f35599ced7aa4fce932de9_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\fdba91e981b515d2db5442d762ea1d39_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\fdc8957045c44450a96686ed0567a75c_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\febbdcfc0fc90a36af32c44241c2f950_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ffbc9ff8e746635ffda23a5d7a8b6afc_cc9eee0a-4fa0-4cde-aa76-c21785e3cd84 1340 bytes
File C:\RRbackups\Q 0 bytes
File C:\RRbackups\Q\0 0 bytes
File C:\RRbackups\Q\0\Data0 50003968 bytes
File C:\RRbackups\Q\0\Data1 50003968 bytes
File C:\RRbackups\Q\0\Data2 50003968 bytes
File C:\RRbackups\Q\0\Data3 36087695 bytes
File C:\RRbackups\Q\0\dats 0 bytes
File C:\RRbackups\Q\0\EFSFile 0 bytes
File C:\RRbackups\Q\0\HashFile 5244 bytes
File C:\RRbackups\Q\0\Info 756 bytes
File C:\RRbackups\Q\0\TOCFile 533140 bytes
File C:\RRbackups\Q\1 0 bytes
File C:\RRbackups\Q\1\Data0 22903 bytes
File C:\RRbackups\Q\1\dats 0 bytes
File C:\RRbackups\Q\1\EFSFile 0 bytes
File C:\RRbackups\Q\1\HashFile 5250 bytes
File C:\RRbackups\Q\1\Info 756 bytes
File C:\RRbackups\Q\1\TOCFile 533750 bytes
File C:\RRbackups\S 0 bytes
File C:\RRbackups\S\0 0 bytes
File C:\RRbackups\S\0\Data0 50003968 bytes
File C:\RRbackups\S\0\Data1 50003968 bytes
File C:\RRbackups\S\0\Data10 50003968 bytes
File C:\RRbackups\S\0\Data11 50003968 bytes
File C:\RRbackups\S\0\Data12 1152832 bytes
File C:\RRbackups\S\0\Data2 50003968 bytes
File C:\RRbackups\S\0\Data3 50003968 bytes
File C:\RRbackups\S\0\Data4 50003968 bytes
File C:\RRbackups\S\0\Data5 50003968 bytes
File C:\RRbackups\S\0\Data6 50003968 bytes
File C:\RRbackups\S\0\Data7 50003968 bytes
File C:\RRbackups\S\0\Data8 50003968 bytes
File C:\RRbackups\S\0\Data9 50003968 bytes
File C:\RRbackups\S\0\dats 0 bytes
File C:\RRbackups\S\0\EFSFile 0 bytes
File C:\RRbackups\S\0\HashFile 55530 bytes
File C:\RRbackups\S\0\Info 756 bytes
File C:\RRbackups\S\0\TOCFile 5645550 bytes
File C:\RRbackups\S\1 0 bytes
File C:\RRbackups\S\1\Data0 70058 bytes
File C:\RRbackups\S\1\dats 0 bytes
File C:\RRbackups\S\1\EFSFile 0 bytes
File C:\RRbackups\S\1\HashFile 55536 bytes
File C:\RRbackups\S\1\Info 756 bytes
File C:\RRbackups\S\1\TOCFile 5646160 bytes
File C:\RRbackups\SIS 0 bytes
File C:\RRbackups\SIS\C 0 bytes
File C:\RRbackups\SIS\C\0 0 bytes
File C:\RRbackups\SIS\C\0\Data0 25613816 bytes
File C:\RRbackups\SIS\C\0\Data1 121004 bytes
File C:\RRbackups\SIS\C\0\Data2 24425 bytes
File C:\RRbackups\SIS\C\0\Data3 29185 bytes
File C:\RRbackups\SIS\C\0\Data4 8531 bytes
File C:\RRbackups\SIS\C\0\Data5 7987544 bytes
File C:\RRbackups\SIS\C\0\HashFile 36 bytes
File C:\RRbackups\SIS\C\0\TOCFile 3660 bytes
File C:\RRbackups\SIS\Q 0 bytes
File C:\RRbackups\SIS\Q\0 0 bytes
File C:\RRbackups\SIS\S 0 bytes
File C:\RRbackups\SIS\S\0 0 bytes
---- EOF - GMER 1.0.15 ----
From MBERcheck:
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows Vista Business Edition
Windows Information: Service Pack 2 (build 6002), 64-bit
Base Board Manufacturer: LENOVO
BIOS Manufacturer: LENOVO
System Manufacturer: LENOVO
System Product Name: 7465CTO
Logical Drives Mask: 0x0005000c
Kernel Drivers (total 177):
0x02A15000 \SystemRoot\system32\ntoskrnl.exe
0x02F2D000 \SystemRoot\system32\hal.dll
0x0060A000 \SystemRoot\system32\kdcom.dll
0x00614000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x0064F000 \SystemRoot\system32\PSHED.dll
0x00663000 \SystemRoot\system32\CLFS.SYS
0x006C0000 \SystemRoot\system32\CI.dll
0x00800000 \SystemRoot\system32\drivers\Wdf01000.sys
0x008DA000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x008E8000 \SystemRoot\system32\drivers\acpi.sys
0x0093E000 \SystemRoot\system32\drivers\WMILIB.SYS
0x00947000 \SystemRoot\system32\drivers\msisadrv.sys
0x00951000 \SystemRoot\system32\drivers\pci.sys
0x00981000 \SystemRoot\System32\drivers\partmgr.sys
0x00996000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x0099A000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x009A6000 \SystemRoot\system32\drivers\volmgr.sys
0x00772000 \SystemRoot\System32\drivers\volmgrx.sys
0x009BA000 \SystemRoot\system32\drivers\pciide.sys
0x009C1000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x009D1000 \SystemRoot\System32\drivers\mountmgr.sys
0x00A07000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x00B24000 \SystemRoot\system32\drivers\atapi.sys
0x00B2C000 \SystemRoot\system32\drivers\ataport.SYS
0x00B50000 \SystemRoot\system32\drivers\msahci.sys
0x00B5A000 \SystemRoot\system32\drivers\fltmgr.sys
0x00BA1000 \SystemRoot\system32\drivers\fileinfo.sys
0x00BB5000 \SystemRoot\System32\Drivers\DRVECDB.SYS
0x00BD2000 \SystemRoot\System32\Drivers\PxHlpa64.sys
0x00C0C000 \SystemRoot\System32\Drivers\ksecdd.sys
0x00E0B000 \SystemRoot\system32\drivers\ndis.sys
0x00C93000 \SystemRoot\system32\drivers\msrpc.sys
0x00CE3000 \SystemRoot\system32\drivers\NETIO.SYS
0x01009000 \SystemRoot\System32\drivers\tcpip.sys
0x0117F000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x0120C000 \SystemRoot\System32\Drivers\Ntfs.sys
0x0138C000 \SystemRoot\system32\drivers\volsnap.sys
0x013D0000 \SystemRoot\System32\DRIVERS\ApsHM64.sys
0x013DA000 \SystemRoot\System32\Drivers\spldr.sys
0x011AB000 \SystemRoot\System32\DRIVERS\Apsx64.sys
0x013E2000 \SystemRoot\System32\Drivers\mup.sys
0x011CF000 \SystemRoot\System32\drivers\ecache.sys
0x00FCE000 \SystemRoot\system32\drivers\disk.sys
0x00D3C000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x013F4000 \SystemRoot\system32\drivers\crcdisk.sys
0x02328000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x02335000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x0233E000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x02404000 \SystemRoot\system32\DRIVERS\igdkmd64.sys
0x02C0B000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x02CEE000 \SystemRoot\System32\drivers\watchdog.sys
0x02CFE000 \SystemRoot\system32\DRIVERS\HECIx64.sys
0x02D0F000 \SystemRoot\system32\DRIVERS\serial.sys
0x02D2C000 \SystemRoot\system32\DRIVERS\serenum.sys
0x02D38000 \SystemRoot\system32\DRIVERS\e1y60x64.sys
0x02D88000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x02D94000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x02DDA000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x02E05000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x0300A000 \SystemRoot\system32\DRIVERS\NETw5v64.sys
0x034AF000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x034C5000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x034D3000 \SystemRoot\system32\DRIVERS\tp4track.sys
0x034DF000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x034EB000 \SystemRoot\system32\drivers\tpm.sys
0x034FB000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x03500000 \SystemRoot\system32\DRIVERS\ibmpmdrv.sys
0x0350B000 \SystemRoot\System32\Drivers\DLACDBHE.SYS
0x0350E000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x0352A000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x03537000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x03540000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x03579000 \SystemRoot\system32\DRIVERS\storport.sys
0x035D6000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x02EF2000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x02F15000 \SystemRoot\system32\DRIVERS\mux.sys
0x035E3000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x02F94000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x035EF000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x02FC5000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x02FE3000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x02351000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0x02DEB000 \SystemRoot\system32\DRIVERS\termdd.sys
0x02B91000 \SystemRoot\system32\DRIVERS\psadd.sys
0x02B9D000 \SystemRoot\system32\DRIVERS\Tvti2c.sys
0x03000000 \SystemRoot\system32\DRIVERS\swenum.sys
0x02BAB000 \SystemRoot\system32\DRIVERS\ks.sys
0x02C00000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x02BDF000 \SystemRoot\system32\DRIVERS\umbus.sys
0x00D68000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x023EB000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x04A0D000 \SystemRoot\system32\drivers\CHDRT64.sys
0x04AAC000 \SystemRoot\system32\drivers\portcls.sys
0x04AE7000 \SystemRoot\system32\drivers\drmk.sys
0x04B0A000 \SystemRoot\system32\drivers\ksthunk.sys
0x04B10000 \SystemRoot\system32\DRIVERS\CAXHWAZL.sys
0x04C0F000 \SystemRoot\system32\DRIVERS\CAX_DPV.sys
0x04E0F000 \SystemRoot\system32\DRIVERS\CAX_CNXT.sys
0x04EDA000 \SystemRoot\system32\drivers\modem.sys
0x04EFC000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x04F06000 \SystemRoot\System32\Drivers\Null.SYS
0x04F0F000 \SystemRoot\System32\Drivers\DLARTL_E.SYS
0x04F22000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x04F2A000 \SystemRoot\System32\drivers\vga.sys
0x04F38000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x04F5D000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x04F66000 \SystemRoot\system32\drivers\rdpencdd.sys
0x04F6F000 \SystemRoot\System32\Drivers\Msfs.SYS
0x04F7A000 \SystemRoot\System32\Drivers\Npfs.SYS
0x04F8B000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x04F94000 \SystemRoot\system32\DRIVERS\tdx.sys
0x04FB1000 \SystemRoot\system32\DRIVERS\smb.sys
0x04D83000 \SystemRoot\system32\drivers\afd.sys
0x04B63000 \SystemRoot\System32\DRIVERS\netbt.sys
0x04FCC000 \SystemRoot\system32\DRIVERS\pacer.sys
0x04FEA000 \SystemRoot\system32\DRIVERS\netbios.sys
0x04BA7000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x04FF9000 \SystemRoot\System32\drivers\Tppwr64v.sys
0x04E00000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
0x04EE9000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
0x04BC2000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x04EF3000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x00DB0000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x04BDE000 \SystemRoot\system32\DRIVERS\5U875.sys
0x04DEE000 \SystemRoot\system32\DRIVERS\STREAM.SYS
0x04C00000 \SystemRoot\system32\drivers\nsiproxy.sys
0x04EF5000 \SystemRoot\system32\DRIVERS\smiifx64.sys
0x05002000 \SystemRoot\system32\drivers\csc.sys
0x05078000 \SystemRoot\System32\Drivers\dfsc.sys
0x05095000 \SystemRoot\system32\DRIVERS\avipbb.sys
0x050B7000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x050C0000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x050D2000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x050DD000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x050E8000 \SystemRoot\System32\Drivers\crashdmp.sys
0x02200000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x00000000 \SystemRoot\System32\win32k.sys
0x050F6000 \SystemRoot\System32\drivers\Dxapi.sys
0x05102000 \SystemRoot\system32\DRIVERS\monitor.sys
0x00410000 \SystemRoot\System32\TSDDD.dll
0x00690000 \SystemRoot\System32\cdd.dll
0x05115000 \SystemRoot\system32\drivers\luafv.sys
0x05137000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0x05154000 \SystemRoot\system32\DRIVERS\tvtfilter.sys
0x05163000 \SystemRoot\System32\Drivers\DRVEDDM.SYS
0x05171000 \SystemRoot\System32\DLA\DLADResE.SYS
0x05172000 \SystemRoot\System32\DLA\DLAIFS_E.SYS
0x05194000 \SystemRoot\System32\DLA\DLAOPIOE.SYS
0x0519B000 \SystemRoot\System32\DLA\DLAPoolE.SYS
0x0519E000 \SystemRoot\System32\DLA\DLABMFSE.SYS
0x051A8000 \SystemRoot\System32\DLA\DLABOIOE.SYS
0x051B1000 \SystemRoot\System32\DLA\DLAUDFAE.SYS
0x051D1000 \SystemRoot\System32\DLA\DLAUDF_E.SYS
0x1580A000 \SystemRoot\system32\drivers\spsys.sys
0x158A4000 \SystemRoot\system32\DRIVERS\irda.sys
0x158C7000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x158DB000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x1590F000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x1591A000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x15932000 \SystemRoot\system32\drivers\HTTP.sys
0x159D5000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x00FE2000 \SystemRoot\system32\DRIVERS\bowser.sys
0x00BDE000 \SystemRoot\System32\drivers\mpsdrv.sys
0x007D8000 \SystemRoot\system32\drivers\mrxdav.sys
0x15E0B000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x15E34000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x15E7D000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x15E9C000 \SystemRoot\System32\DRIVERS\srv2.sys
0x15ECE000 \SystemRoot\System32\DRIVERS\srv.sys
0x15F61000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0x1640C000 \SystemRoot\system32\drivers\peauth.sys
0x164C2000 \SystemRoot\System32\Drivers\secdrv.SYS
0x164CD000 \SystemRoot\System32\drivers\tcpipreg.sys
0x164DD000 \SystemRoot\system32\DRIVERS\xaudio64.sys
0x164E5000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x16501000 \??\C:\Windows\system32\drivers\mbam.sys
0x76F80000 \Windows\System32\ntdll.dll
Processes (total 122):
0 System Idle Process
4 System
496 C:\Windows\System32\smss.exe
628 csrss.exe
664 C:\Windows\System32\wininit.exe
684 csrss.exe
720 C:\Windows\System32\services.exe
732 C:\Windows\System32\lsass.exe
740 C:\Windows\System32\lsm.exe
820 C:\Windows\System32\winlogon.exe
928 C:\Windows\System32\svchost.exe
1012 C:\Windows\System32\ibmpmsvc.exe
376 C:\Windows\System32\svchost.exe
688 C:\Windows\System32\svchost.exe
736 C:\Windows\System32\svchost.exe
1036 C:\Windows\System32\svchost.exe
1100 C:\Windows\System32\audiodg.exe
1124 C:\Windows\System32\svchost.exe
1180 C:\Windows\System32\SLsvc.exe
1220 C:\Windows\System32\svchost.exe
1332 C:\Windows\System32\svchost.exe
1456 C:\Windows\System32\wlanext.exe
1584 C:\Windows\System32\spoolsv.exe
1608 C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
1624 C:\Windows\System32\svchost.exe
1820 C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
1868 C:\Program Files\SUPERAntiSpyware\SASCore64.exe
1880 C:\Program Files (x86)\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
1932 C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
1948 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1972 C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
1996 C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
2016 C:\Program Files (x86)\Bonjour\mDNSResponder.exe
2040 C:\Program Files\Intel\WiFi\bin\EvtEng.exe
1736 C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService .exe
1048 C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
2160 C:\Program Files (x86)\Intel\AMT\LMS.exe
2184 C:\Windows\System32\svchost.exe
2208 C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe
2240 C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
2376 C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
2416 C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
2464 C:\Windows\System32\svchost.exe
2516 C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
2528 C:\Windows\System32\TPHDEXLG64.exe
2552 C:\Program Files (x86)\Lenovo\Client Security Solution\tvttcsd.exe
2564 C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrpservice.exe
2580 C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
2608 C:\Program Files (x86)\Common Files\Lenovo\Scheduler\tvtsched.exe
2696 C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe
2808 C:\Windows\System32\svchost.exe
792 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
2384 C:\Windows\System32\SearchIndexer.exe
2332 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
2900 C:\Windows\System32\drivers\XAudio64.exe
2308 WmiPrvSE.exe
3308 C:\Windows\System32\taskeng.exe
3392 C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
3420 C:\Windows\System32\dwm.exe
3472 C:\Windows\explorer.exe
3560 C:\Program Files (x86)\ThinkPad\ConnectUtilities\AcSvc.exe
3772 C:\Program Files (x86)\Lenovo\System Update\SUService.exe
3932 C:\Program Files (x86)\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
4072 C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
3684 WmiPrvSE.exe
4592 C:\Program Files\Lenovo\TrackPoint\tp4serv.exe
4612 C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe
4620 C:\Windows\System32\taskeng.exe
4636 C:\Windows\System32\TpShocks.exe
4648 C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
4704 C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
4728 C:\Program Files\Lenovo\HOTKEY\tpfnf6r.exe
4780 C:\Windows\System32\igfxtray.exe
4816 C:\Windows\System32\hkcmd.exe
4824 C:\Windows\System32\igfxpers.exe
4836 C:\Program Files\Java\jre6\bin\jusched.exe
4852 C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
4872 C:\Program Files\Windows Sidebar\sidebar.exe
4924 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
4976 C:\Windows\System32\igfxsrvc.exe
5052 C:\Program Files (x86)\Digital Line Detect\DLG.exe
5060 C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
5068 C:\Program Files (x86)\RotateImage\RCIMGDIR.exe
5088 C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
3744 C:\Program Files (x86)\Lenovo\NPDIRECT\tpfnf7sp.exe
2252 C:\Program Files (x86)\ThinkPad\Utilities\EZEJMNAP.EXE
4120 C:\Program Files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
2860 C:\Program Files (x86)\ThinkVantage\PrdCtr\LPMGR.EXE
2844 C:\Program Files (x86)\ThinkVantage\PrdCtr\LPMLCHK.EXE
2840 C:\Program Files (x86)\ThinkVantage\AMSG\Amsg.exe
2976 C:\Program Files (x86)\Lenovo2\Drag-to-Disc\DrgToDsc.exe
160 C:\Windows\SysWOW64\rundll32.exe
3720 C:\Program Files\Lenovo\ZOOM\TpScrex.exe
4112 C:\Program Files (x86)\ThinkPad\ConnectUtilities\ACTray.exe
4216 C:\Program Files (x86)\ThinkPad\ConnectUtilities\ACWLIcon.exe
896 C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
2724 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
960 C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
4504 C:\Program Files (x86)\iTunes\iTunesHelper.exe
4460 C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
4296 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
1844 C:\Program Files (x86)\Lenovo\Camera Center\bin\LenovoCameraCenter.exe
4480 C:\Windows\System32\rundll32.exe
5296 C:\Program Files\iPod\bin\iPodService.exe
3800 C:\Windows\System32\svchost.exe
3656 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMUIAux.EXE
5464 C:\Program Files (x86)\Yahoo!\Messenger\Ymsgr_tray.exe
5976 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
3120 C:\Windows\System32\wuauclt.exe
5828 C:\Program Files (x86)\Internet Explorer\iexplore.exe
4184 C:\Program Files (x86)\Internet Explorer\iexplore.exe
3172 C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_Ac tiveX.exe
5132 C:\Program Files (x86)\Internet Explorer\iexplore.exe
4576 C:\Users\lqi\Desktop\anti_virus\20zu1ehy.exe
5880 C:\Windows\System32\SearchProtocolHost.exe
4564 C:\Windows\System32\SearchFilterHost.exe
4632 C:\Program Files (x86)\Internet Explorer\iexplore.exe
5960 C:\Windows\System32\SearchProtocolHost.exe
2908 dllhost.exe
5224 dllhost.exe
4752 C:\Users\lqi\Desktop\anti_virus\MBRCheck.exe
2364 C:\Windows\SysWOW64\conime.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`5dd00000 (NTFS)
\\.\Q: --> \\.\PhysicalDrive0 at offset 0x00000037`c7a00000 (NTFS)
\\.\S: --> \\.\PhysicalDrive0 at offset 0x00000000`00100000 (NTFS)
PhysicalDrive0 Model Number: WDCWD2500BEVS-08VAT2, Rev: 14.01A14
Size Device Name MBR Status
--------------------------------------------
232 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979
Done!
From DDS:
.
DDS (Ver_2011-06-03.01) - NTFSAMD64
Internet Explorer: 8.0.6001.19048 BrowserJavaVersion: 1.6.0_21
Run by lqi at 13:45:44 on 2011-06-04
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.2967.920 [GMT -4:00]
.
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService .exe
C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files (x86)\Intel\AMT\LMS.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
c:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Windows\System32\TPHDEXLG64.exe
C:\Program Files (x86)\Lenovo\Client Security Solution\tvttcsd.exe
C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrpservice.exe
C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
c:\Program Files (x86)\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\DRIVERS\xaudio64.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\ThinkPad\ConnectUtilities\AcSvc.exe
c:\Program Files (x86)\Lenovo\System Update\SUService.exe
C:\Program Files (x86)\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Lenovo\TrackPoint\tp4serv.exe
C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\TpShocks.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\Program Files\Lenovo\HOTKEY\tpfnf6r.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\Digital Line Detect\DLG.exe
C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files (x86)\RotateImage\RCIMGDIR.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files (x86)\Lenovo\NPDIRECT\tpfnf7sp.exe
C:\Program Files (x86)\ThinkPad\Utilities\EZEJMNAP.EXE
C:\Program Files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files (x86)\ThinkVantage\PrdCtr\LPMGR.EXE
C:\Program Files (x86)\ThinkVantage\PrdCtr\LPMLCHK.EXE
C:\Program Files (x86)\ThinkVantage\AMSG\Amsg.exe
C:\Program Files (x86)\Lenovo2\Drag-to-Disc\DrgToDsc.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files (x86)\ThinkPad\ConnectUtilities\ACTray.exe
C:\Program Files (x86)\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Lenovo\Camera Center\bin\LenovoCameraCenter.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\PROGRA~2\ThinkPad\UTILIT~1\PWMUIAux.exe
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_Ac tiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\lqi\Desktop\anti_virus\20zu1ehy.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\SysWOW64\conime.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.yahoo.com
uDefault_Page_URL = hxxp://lenovo.live.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
mDefault_Page_URL = hxxp://lenovo.live.com
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: IePasswordManagerHelper Class: {bf468356-bb7e-42d7-9f15-4f3b9bcfced2} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - C:\Program Files (x86)\WOT\WOT.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - C:\Program Files (x86)\WOT\WOT.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.e xe" -quiet
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [TPFNF7] "C:\Program Files (x86)\Lenovo\NPDIRECT\TPFNF7SP.exe" /r
mRun: [EZEJMNAP] C:\PROGRA~2\ThinkPad\UTILIT~1\EzEjMnAp.Exe
mRun: [TVT Scheduler Proxy] C:\Program Files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
mRun: [LPManager] C:\PROGRA~2\THINKV~1\PrdCtr\LPMGR.exe
mRun: [LPMailChecker] C:\PROGRA~2\THINKV~1\PrdCtr\LPMLCHK.exe
mRun: [AMSG] "C:\Program Files (x86)\ThinkVantage\AMSG\Amsg.exe" /startup
mRun: [CameraApplicationLauncher] C:\Program Files (x86)\Lenovo\Camera Center\bin\CameraApplicationLaunchpadLauncher.exe
mRun: [RoxioDragToDisc] "C:\Program Files (x86)\Lenovo2\Drag-to-Disc\DrgToDsc.exe"
mRun: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrB kGndMonitor
mRun: [BLOG] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\BTVLogEx.DLL,StartBa ttLog
mRun: [CreateLMBCShortCut] "C:\Program Files (x86)\Lenovo\Mobile Broadband Connect\UserShortcutCreator.exe"
mRun: [ACTray] C:\Program Files (x86)\ThinkPad\ConnectUtilities\ACTray.exe
mRun: [ACWlIcon] C:\Program Files (x86)\ThinkPad\ConnectUtilities\ACWlIcon.exe
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [CarboniteSetupLite] "C:\Program Files (x86)\Carbonite\CarbonitePreinstaller.exe" /preinstalled /showonfirst /reshowat=900
mRun: [MaxMenuMgr] "C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Sta rtup\DIGITA~1.LNK - C:\Program Files (x86)\Digital Line Detect\DLG.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Sta rtup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Sta rtup\RCIMGD~1.LNK - C:\Program Files (x86)\RotateImage\RCIMGDIR.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
IE: {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {AC414988-E5BB-4C2C-873B-EA53D2F3D23A} - hxxp://t.live.cctv.com/ieocx/CCTVUpdateInstall.dll
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
TCP: DhcpNameServer = 68.87.68.166 68.87.74.166
TCP: Interfaces\{395AFEDA-7FBE-45D7-959C-3C3D7D883C12} : NameServer = 0.0.0.0
TCP: Interfaces\{3DE8E9A3-8AFA-4182-A6DF-C0CB2B68C0A9} : DhcpNameServer = 68.87.68.166 68.87.74.166
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll
AppInit_DLLs: acaptuser32.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
LSA: Notification Packages = scecli ACGina
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO-X64: IePasswordManagerHelper Class: {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
BHO-X64: Password Manager Browser Helper Object - No File
BHO-X64: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO-X64: SmartSelect - No File
TB-X64: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB-X64: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll
mRun-x64: [TPFNF7] "C:\Program Files (x86)\Lenovo\NPDIRECT\TPFNF7SP.exe" /r
mRun-x64: [EZEJMNAP] C:\PROGRA~2\ThinkPad\UTILIT~1\EzEjMnAp.Exe
mRun-x64: [TVT Scheduler Proxy] C:\Program Files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
mRun-x64: [LPManager] C:\PROGRA~2\THINKV~1\PrdCtr\LPMGR.exe
mRun-x64: [LPMailChecker] C:\PROGRA~2\THINKV~1\PrdCtr\LPMLCHK.exe
mRun-x64: [AMSG] "C:\Program Files (x86)\ThinkVantage\AMSG\Amsg.exe" /startup
mRun-x64: [CameraApplicationLauncher] C:\Program Files (x86)\Lenovo\Camera Center\bin\CameraApplicationLaunchpadLauncher.exe
mRun-x64: [RoxioDragToDisc] "C:\Program Files (x86)\Lenovo2\Drag-to-Disc\DrgToDsc.exe"
mRun-x64: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrB kGndMonitor
mRun-x64: [BLOG] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\BTVLogEx.DLL,StartBa ttLog
mRun-x64: [CreateLMBCShortCut] "C:\Program Files (x86)\Lenovo\Mobile Broadband Connect\UserShortcutCreator.exe"
mRun-x64: [ACTray] C:\Program Files (x86)\ThinkPad\ConnectUtilities\ACTray.exe
mRun-x64: [ACWlIcon] C:\Program Files (x86)\ThinkPad\ConnectUtilities\ACWlIcon.exe
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
mRun-x64: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [CarboniteSetupLite] "C:\Program Files (x86)\Carbonite\CarbonitePreinstaller.exe" /preinstalled /showonfirst /reshowat=900
mRun-x64: [MaxMenuMgr] "C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun-x64: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
AppInit_DLLs-X64: acaptuser32.dll
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\lqi\AppData\Roaming\Mozilla\Firefox\Profi les\d7tyfmwv.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R0 DRVECDB;DRVECDB;C:\Windows\system32\Drivers\DRVECD B.SYS --> C:\Windows\system32\Drivers\DRVECDB.SYS [?]
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHl pa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R0 TPDIGIMN;TPDIGIMN;C:\Windows\system32\DRIVERS\ApsH M64.sys --> C:\Windows\system32\DRIVERS\ApsHM64.sys [?]
R1 DLACDBHE;DLACDBHE;C:\Windows\system32\Drivers\DLAC DBHE.SYS --> C:\Windows\system32\Drivers\DLACDBHE.SYS [?]
R1 DLARTL_E;DLARTL_E;C:\Windows\system32\Drivers\DLAR TL_E.SYS --> C:\Windows\system32\Drivers\DLARTL_E.SYS [?]
R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\system32\DRIVERS\smiifx64.sys --> C:\Windows\system32\DRIVERS\smiifx64.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-17 14920]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-17 12360]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2010-6-29 128752]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2011-6-3 136360]
R2 AntiVirService;Avira AntiVir Guard;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2011-6-3 269480]
R2 avgntflt;avgntflt;C:\Windows\system32\DRIVERS\avgn tflt.sys --> C:\Windows\system32\DRIVERS\avgntflt.sys [?]
R2 DLABMFSE;DLABMFSE;C:\Windows\system32\DLA\DLABMFSE .SYS --> C:\Windows\system32\DLA\DLABMFSE.SYS [?]
R2 DLABOIOE;DLABOIOE;C:\Windows\system32\DLA\DLABOIOE .SYS --> C:\Windows\system32\DLA\DLABOIOE.SYS [?]
R2 DLADResE;DLADResE;C:\Windows\system32\DLA\DLADResE .SYS --> C:\Windows\system32\DLA\DLADResE.SYS [?]
R2 DLAIFS_E;DLAIFS_E;C:\Windows\system32\DLA\DLAIFS_E .SYS --> C:\Windows\system32\DLA\DLAIFS_E.SYS [?]
R2 DLAOPIOE;DLAOPIOE;C:\Windows\system32\DLA\DLAOPIOE .SYS --> C:\Windows\system32\DLA\DLAOPIOE.SYS [?]
R2 DLAPoolE;DLAPoolE;C:\Windows\system32\DLA\DLAPoolE .SYS --> C:\Windows\system32\DLA\DLAPoolE.SYS [?]
R2 DLAUDF_E;DLAUDF_E;C:\Windows\system32\DLA\DLAUDF_E .SYS --> C:\Windows\system32\DLA\DLAUDF_E.SYS [?]
R2 DLAUDFAE;DLAUDFAE;C:\Windows\system32\DLA\DLAUDFAE .SYS --> C:\Windows\system32\DLA\DLAUDFAE.SYS [?]
R2 DRVEDDM;DRVEDDM;C:\Windows\system32\Drivers\DRVEDD M.SYS --> C:\Windows\system32\Drivers\DRVEDDM.SYS [?]
R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 FreeAgentGoNext Service;Seagate Service;C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService .exe [2009-9-26 189736]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2010-8-5 366640]
R2 Power Manager DBC Service;Power Manager DBC Service;C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe [2009-8-5 66848]
R2 TPHKSVC;On Screen Display;C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe [2009-6-12 62320]
R2 TVT Backup Protection Service;TVT Backup Protection Service;C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrpservice.exe [2008-5-24 520192]
R2 UNS;Intel(R) Active Management Technology User Notification Service;C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2009-8-5 2058776]
R3 5U875UVC;Integrated Camera;C:\Windows\system32\DRIVERS\5U875.sys --> C:\Windows\system32\DRIVERS\5U875.sys [?]
R3 CAXHWAZL;CAXHWAZL;C:\Windows\system32\DRIVERS\CAXH WAZL.sys --> C:\Windows\system32\DRIVERS\CAXHWAZL.sys [?]
R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;C:\Windows\system32\DRIVERS\e1y60x64.sys --> C:\Windows\system32\DRIVERS\e1y60x64.sys [?]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system3 2\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 MUXMP;My WiFi PAN MUX-IM Virtual Miniport Driver;C:\Windows\system32\DRIVERS\mux.sys --> C:\Windows\system32\DRIVERS\mux.sys [?]
R3 NETw5v64;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 64 Bit ;C:\Windows\system32\DRIVERS\NETw5v64.sys --> C:\Windows\system32\DRIVERS\NETw5v64.sys [?]
R3 Tp4Track;PS/2 TrackPoint Driver;C:\Windows\system32\DRIVERS\tp4track.sys --> C:\Windows\system32\DRIVERS\tp4track.sys [?]
R3 TVTI2C;Lenovo SM bus driver;C:\Windows\system32\DRIVERS\Tvti2c.sys --> C:\Windows\system32\DRIVERS\Tvti2c.sys [?]
S1 tvtumon;tvtumon;C:\Windows\system32\DRIVERS\tvtumo n.sys --> C:\Windows\system32\DRIVERS\tvtumon.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\ v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework6 4\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 LENOVO.MICMUTE;Lenovo Microphone Mute;C:\Program Files\Lenovo\HOTKEY\micmute.exe [2009-6-12 45424]
S2 TVT_UpdateMonitor;TVT Windows Update Monitor;C:\Program Files (x86)\Lenovo\Rescue and Recovery\UpdateMonitor.exe [2008-5-24 360448]
S2 WebUpdate4;Web Update Wizard Service V4;C:\Windows\SysWOW64\WebUpdateSvc4.exe --> C:\Windows\SysWOW64\WebUpdateSvc4.exe [?]
S3 ICDUSB3;ICDUSB3;C:\Windows\system32\Drivers\ICDUSB 3.sys --> C:\Windows\system32\Drivers\ICDUSB3.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 MosIrUsb;MosIrUsb.sys;C:\Windows\system32\DRIVERS\ MosIrUsb.sys --> C:\Windows\system32\DRIVERS\MosIrUsb.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;C:\Windows\system32\DRIVERS\motccgp.sys --> C:\Windows\system32\DRIVERS\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;C:\Windows\system32\DRI VERS\motccgpfl.sys --> C:\Windows\system32\DRIVERS\motccgpfl.sys [?]
S3 MUXP;My WiFi PAN Mux-IM Protocol Driver;C:\Windows\system32\DRIVERS\mux.sys --> C:\Windows\system32\DRIVERS\mux.sys [?]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2009-2-11 306688]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 PSI;PSI;C:\Windows\system32\DRIVERS\psi_mf.sys --> C:\Windows\system32\DRIVERS\psi_mf.sys [?]
S3 RoxMediaDB10;RoxMediaDB10;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2008-4-25 1120752]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0. 30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework6 4\v2.0.50727\mscorsvw.exe [2010-8-15 89920]
.
=============== File Associations ===============
.
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2011-06-04 14:07:39 -------- d-----w- C:\Users\lqi\AppData\Local\{47C613AD-D7AD-41CA-B28D-7BAE879DC7E7}
2011-06-03 16:22:20 83120 ----a-w- C:\Windows\System32\drivers\avgntflt.sys
2011-06-03 16:22:19 -------- d-----w- C:\ProgramData\Avira
2011-06-03 16:22:19 -------- d-----w- C:\Program Files (x86)\Avira
2011-06-03 16:07:19 8718160 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1B5AFB27-65F2-4991-9128-B4545837DD54}\mpengine.dll
2011-06-03 16:01:08 -------- d-----w- C:\Users\lqi\AppData\Local\{86012517-AA7B-47DA-BF15-62511678C91F}
2011-06-02 15:48:34 -------- d-----w- C:\Users\lqi\AppData\Roaming\SUPERAntiSpyware.com
2011-06-02 15:48:34 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2011-06-02 15:48:29 -------- d-----w- C:\ProgramData\!SASCORE
2011-06-02 15:48:25 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2011-06-02 14:51:32 -------- d-sh--w- C:\ProgramData\PSRAYUJG
2011-06-02 14:51:12 -------- d-sh--w- C:\ProgramData\9c9680
2011-06-02 14:08:51 -------- d-----w- C:\Users\lqi\AppData\Local\{F05907DF-7EDD-4423-856A-D0FF4380B98B}
2011-06-01 22:33:41 -------- d-----w- C:\Users\lqi\AppData\Local\{2599A179-C367-462C-9D09-C9BE144C6151}
2011-05-31 21:54:50 -------- d-----w- C:\Users\lqi\AppData\Local\{44B609B0-D76B-496D-AC23-F2683C36463E}
2011-05-31 14:27:23 -------- d-----w- C:\Users\lqi\AppData\Local\{30974079-FCC4-4FEB-A28C-6686553205B4}
2011-05-29 17:32:22 -------- d-----w- C:\Users\lqi\AppData\Local\{22AB9743-4382-4C46-9A18-DB1103E2C332}
2011-05-28 17:43:22 -------- d-----w- C:\Users\lqi\AppData\Local\{3D83FBD6-96BA-49FE-90F2-57E21AED61F2}
2011-05-27 21:03:17 -------- d-----w- C:\Users\lqi\AppData\Local\{6027B214-2254-41E9-BA0C-27EDBB51444D}
2011-05-26 18:59:30 -------- d-----w- C:\Users\lqi\AppData\Local\{7FACE21B-7B07-4C40-9A7A-769005C6C280}
2011-05-26 13:47:47 -------- d-----w- C:\Users\lqi\AppData\Local\{B5227B09-562F-4738-AB91-BCCFDAF356E0}
2011-05-23 19:23:36 -------- d-----w- C:\Users\lqi\AppData\Local\{1C35662B-EB08-4FC4-B5C9-ACC7E4CD37DB}
2011-05-21 18:23:14 -------- d-----w- C:\Users\lqi\AppData\Local\{70D9CF81-81CF-4274-9FCE-9B1C41CED19F}
2011-05-20 15:44:05 -------- d-----w- C:\Users\lqi\AppData\Local\{71BFEB9D-7CE7-4F25-80D1-1E9647F96F97}
2011-05-19 04:15:46 -------- d-----w- C:\Users\lqi\AppData\Local\{D5BF2E1A-A18A-4EC2-808C-1AE2298F7700}
2011-05-18 15:09:01 -------- d-----w- C:\Users\lqi\AppData\Local\{F9116545-AC47-47C7-8346-7E6E6772E2F6}
2011-05-17 22:01:59 -------- d-----w- C:\Users\lqi\AppData\Local\{846E8560-EBDA-41B6-AEDE-604BD85E5DBC}
2011-05-17 03:12:09 -------- d-----w- C:\Users\lqi\AppData\Local\{DD24F0E7-5723-4A8E-9052-A220A2931623}
2011-05-16 15:11:31 -------- d-----w- C:\Users\lqi\AppData\Local\{9FB0004E-AFAE-43E5-8351-63728D73657D}
2011-05-15 16:41:32 -------- d-----w- C:\Users\lqi\AppData\Local\{07055C99-2753-4360-95E7-B07ED4C70AC7}
2011-05-15 03:44:43 -------- d-----w- C:\Users\lqi\AppData\Local\{2D540C3C-8AEF-4377-AFB5-B39572D605C2}
2011-05-12 21:47:48 -------- d-----w- C:\Users\lqi\AppData\Local\{73D5611E-8E72-4620-9274-F4D5B6F198CE}
2011-05-12 00:31:17 2409784 ----a-w- C:\Program Files (x86)\Windows Mail\OESpamFilter.dat
2011-05-12 00:31:16 2409784 ----a-w- C:\Program Files\Windows Mail\OESpamFilter.dat
2011-05-12 00:17:01 -------- d-----w- C:\Users\lqi\AppData\Local\{DFD6E4D3-1B0D-4377-9CBB-E7F2087EDD6B}
2011-05-10 02:04:03 -------- d-----w- C:\Users\lqi\AppData\Local\{7E60F79F-2C5A-4799-AECA-3ED34246ED6A}
2011-05-09 23:17:14 -------- d-----w- C:\Users\lqi\AppData\Local\{84E3A561-CA30-4323-B7AF-D0CAF3217DEF}
2011-05-07 14:54:46 -------- d-----w- C:\Users\lqi\AppData\Local\{DE6A09E6-6A1F-46F7-BC63-EAB0EFE6FA58}
.
==================== Find3M ====================
.
2011-05-29 13:11:30 39984 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-05-29 13:11:20 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-03-12 22:52:03 1653760 ----a-w- C:\Windows\System32\XpsPrint.dll
2011-03-12 21:55:52 876032 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2011-03-10 17:18:03 1360384 ----a-w- C:\Windows\System32\mfc42u.dll
2011-03-10 17:18:02 1398784 ----a-w- C:\Windows\System32\mfc42.dll
2011-03-10 17:03:51 1162240 ----a-w- C:\Windows\SysWow64\mfc42u.dll
2011-03-10 17:03:51 1136640 ----a-w- C:\Windows\SysWow64\mfc42.dll
.
============= FINISH: 13:46:25.05 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-03.01)
.
Microsoft® Windows Vista™ Business
Boot Device: \Device\HarddiskVolume1
Install Date: 8/5/2009 12:15:08 PM
System Uptime: 6/4/2011 12:15:53 PM (1 hours ago)
.
Motherboard: LENOVO | | 7465CTO
Processor: Intel(R) Core(TM)2 Duo CPU L9400 @ 1.86GHz | None | 1866/266mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 222 GiB total, 37.887 GiB free.
D: is CDROM ()
Q: is FIXED (NTFS) - 10 GiB total, 2.531 GiB free.
S: is FIXED (NTFS) - 1 GiB total, 0.676 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP473: 5/19/2011 1:09:27 PM - Scheduled Checkpoint
RP474: 5/20/2011 11:51:31 AM - Windows Update
RP475: 5/25/2011 4:14:03 PM - Windows Update
RP476: 5/26/2011 10:41:33 AM - Scheduled Checkpoint
RP477: 5/27/2011 5:10:12 PM - Windows Update
RP478: 5/28/2011 5:31:59 PM - Scheduled Checkpoint
RP479: 5/31/2011 10:34:35 AM - Windows Update
RP480: 6/3/2011 12:06:29 PM - Windows Update
RP481: 6/3/2011 12:15:14 PM - avast! Free Antivirus Setup
RP482: 6/4/2011 1:36:22 PM - Scheduled Checkpoint
.
==== Installed Programs ======================
.
.
Update for Microsoft Office 2007 (KB2508958)
2007 Microsoft Office system
Access Help
Acrobat.com
Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
Adobe Acrobat 9.4.4 - CPSID_83708
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3
Apple Application Support
Apple Software Update
AT&T Service Activation
Avira AntiVir Personal - Free Antivirus
Business Contact Manager for Outlook 2007 SP2
CAJViewer
Camera Center
Canon G.726 WMP-Decoder
Canon MovieEdit Task for ZoomBrowser EX
Canon RAW Image Task for ZoomBrowser EX
Canon Utilities CameraWindow
Canon Utilities CameraWindow DC
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
Canon Utilities MyCamera
Canon Utilities MyCamera DC
Canon Utilities PhotoStitch
Canon Utilities RemoteCapture Task for ZoomBrowser EX
Canon Utilities ZoomBrowser EX
Canon ZoomBrowser EX Memory Card Utility
Carbonite Online Backup Setup
D3DX10
DirectXInstallService
EViews 6
Help Center
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Integrated Camera Driver Installer Package Ver.1.25.500.0
Integrated Camera TWAIN
InterVideo Register Manager
InterVideo WinDVD
Java Auto Updater
Java(TM) 6 Update 21
Lenovo Registration
Lenovo Welcome
Malwarebytes' Anti-Malware version 1.51.0.1200
McAfee Security Scan Plus
Message Center
Microsoft Office 2003 Web Components
Microsoft Office 2007 Primary Interop Assemblies
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Hybrid 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Small Business Connectivity Components
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
Microsoft Silverlight
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
Microsoft SQL Server Setup Support Files (English)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Mobile Broadband Connect
Mozilla Firefox (3.6.8)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee Reveal Seagate Edition
Picasa 3
PowerCmd 2.1
Presentation Director
Product Recovery Disc Burning Utility
Productivity Center Supplement for ThinkPad
QuickTime
Registry patch to improve USB device detection on resume from sleep for Windows Vista
Rescue and Recovery
Roxio Activation Module
Roxio Central Audio
Roxio Central Copy
Roxio Central Core
Roxio Central Data
Roxio Central Tools
Roxio Creator Business Edition
Roxio Express Labeler 3
Safari
Seagate Manager Installer
Secunia PSI
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2466156)
Security Update for 2007 Microsoft Office System (KB2509488)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB2464583)
Security Update for Microsoft Office Groove 2007 (KB2494047)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office Publisher 2007 (KB2284697)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Segoe UI
Sonic CinePlayer Decoder Pack
Sonic Icons for Lenovo
Spelling Dictionaries Support For Adobe Reader 9
Stat/Transfer Nine
Stata 10
System Update
ThinkPad EasyEject Utility
ThinkPad Power Manager
ThinkVantage Access Connections
ThinkVantage Productivity Center
ThinkVantage Technologies Welcome Message
Update for 2007 Microsoft Office System (KB2284654)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2509470)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (KB2536413)
Verizon Wireless Mobile Broadband Self Activation
Wallpapers
Web Update Wizard (Redistributable) 4.0
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Messenger
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
WOT for Internet Explorer
Yahoo! Messenger
Yahoo! Software Update
.
==== Event Viewer Messages From Past Week ========
.
6/4/2011 12:24:53 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TrkWks service.
6/4/2011 12:24:23 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SysMain service.
6/4/2011 12:16:58 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: tvtumon
6/4/2011 12:16:58 PM, Error: Service Control Manager [7023] - The Lenovo Microphone Mute service terminated with the following error: Incorrect function.
6/3/2011 12:22:43 PM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Start with the following error: Access is denied.
6/3/2011 12:00:35 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Irmon service.
6/3/2011 12:00:05 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the hidserv service.
6/3/2011 11:59:35 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the CscService service.
6/3/2011 11:59:05 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AudioEndpointBuilder service.
6/3/2011 1134 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WPDBusEnum service.
6/1/2011 6:42:40 PM, Error: Service Control Manager [7010] - A timeout (30000 milliseconds) was reached while waiting for ReadFile.
6/1/2011 6:32:06 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom tvtumon
5/31/2011 5:55:06 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Font Cache Service service to connect.
5/31/2011 5:55:06 PM, Error: Service Control Manager [7000] - The Windows Font Cache Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
5/31/2011 10:37:09 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.
5/31/2011 10:36:39 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service.
5/28/2011 4:34:19 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Spooler service.
5/28/2011 4:33:15 PM, Error: EventLog [6008] - The previous system shutdown at 4:31:51 PM on 5/28/2011 was unexpected.
5/28/2011 4:26:22 PM, Error: Microsoft-Windows-TBS [516] - An error occurred while communicating with the TPM. The driver returned 0x8007001f.
5/28/2011 4:26:22 PM, Error: Microsoft-Windows-TBS [16385] - An internal TBS error was detected. The error code was 0x8007001f. This is usually caused by unexpected TPM or driver behavior and may be transient.
.
==== End Of File ===========================
Please, do NOT create new topic just to post your logs.
Continue everything right in this topic.
This time, I merged both topics.
================================================== =========
Please download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
- Please, never rename Combofix unless instructed.
- Close any open browsers.
- Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
NOTE1. If Combofix asks you to install Recovery Console, please allow it.
NOTE 2. If Combofix asks you to update the program, always do so.
- Close any open browsers.
- WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
- Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
- If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
- Double click on combofix.exe & follow the prompts.
- When finished, it will produce a report for you.
- Please post the "C:\ComboFix.txt"
**Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
**Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
Use AppRemover to uninstall it: Uninstall & Remove McAfee, Symantec, Norton, AVG, Avast & More Antivirus and Security Applications and Programs
We can reinstall it when we're done with CF.
**Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.
Make sure, you re-enable your security programs, when you're done with Combofix.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~
NOTE.
If, for some reason, Combofix refuses to run, try one of the following:
1. Run Combofix from Safe Mode.
2. Delete Combofix file, download fresh one, but rename combofix.exe to yourname.exe BEFORE saving it to your desktop.
Do NOT run it yet.
Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
There are 4 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click Rkill and choose Run as Administrator
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
Rkill.com
Rkill.scr
Rkill.exe
- Double-click on the Rkill desktop icon to run the tool.
- If using Vista or Windows 7 right-click on it and choose Run As Administrator.
- A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
- If not, delete the file, then download and use the one provided in Link 2.
- If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
- Do not reboot until instructed.
- If the tool does not run from any of the links provided, please let me know.
Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.
If normal mode still doesn't work, run BOTH tools from safe mode.
In case #2, please post BOTH logs, rKill and Combofix.
DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
I disabled firewall and other anti virus programs such as Avira. I ran combo fix. However, I didn't sit in front of the computer while combo fix was running. When returned, i saw the log in screen. So I am not sure whether combofix restartes my computer. I logged on and saw combofix's screen showing the message that says it's preparing log results. But for some reason, Avira popped a window that says that "guard: malware found. A virus or unwanted program 'TR/CryptXPACK.Gen' was found in file 'C:\ComboFix\handle.cfxxe.' access to this file was denied. Please select further section." then the choices are remove and details. Meanwhile the combofix screen displayed the log results after 5 minutes. I don't know why Avira became snaked again. Can you tell me whether i should choose remove or details? I tries to just close this window but it popped up again.
Sorry I was using ipod to type in the last reply. So there were many typos. I meant why Avira started again (not "snaked")...
Also, I forgot to paste the log results from combofix. Strangely I didn't find the log file at the location of C:\ComboFix.txt. But here is what showed up on the screen after ComboFix ran:
ComboFix 11-06-05.01 - lqi 06/05/2011 12:43:42.1.2 - x64
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.2967.1538 [GMT -4:00]
Running from: c:\users\lqi\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\data
c:\data\4type_bysession_5percent
c:\data\aa
c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\ANTIGEN.exe
c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\CLSV.exe
c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\dudl.exe
c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\eb.dll
c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\energy.exe
c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\energy.sys
c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\fan.drv
c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\grid.tmp
c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\kernel32.drv
c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\kernel32.sys
c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\PE.dll
c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\PE.exe
c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\ppal.sys
c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\SICKBOY.drv
c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\SICKBOY.tmp
c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\SM.dll
c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\tjd.drv
c:\users\lqi\AppData\Roaming\Microsoft\Windows\Rec ent\tjd.tmp
c:\windows\system32\Thumbs.db
Q:\AUTORUN.INF
S:\AUTORUN.INF
.
.
((((((((((((((((((((((((( Files Created from 2011-05-05 to 2011-06-05 )))))))))))))))))))))))))))))))
.
.
2011-06-05 17:03 . 2011-06-05 17:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-05 16:32 . 2011-06-05 16:32 -------- d-----w- c:\users\lqi\AppData\Local\{47A5C596-0B08-4769-A746-B16A23003106}
2011-06-05 16:10 . 2011-06-05 16:10 -------- d-----w- c:\users\lqi\AppData\Local\{24B392F0-C4B7-449D-94AA-C89E95CE0462}
2011-06-04 18:13 . 2011-06-04 18:13 -------- d-----w- c:\program files\iPod
2011-06-04 18:13 . 2011-06-04 18:14 -------- d-----w- c:\program files\iTunes
2011-06-04 18:08 . 2011-06-04 18:08 -------- d-----w- c:\program files\Bonjour
2011-06-04 18:08 . 2011-06-04 18:08 -------- d-----w- c:\program files (x86)\Bonjour
2011-06-04 14:07 . 2011-06-04 14:07 -------- d-----w- c:\users\lqi\AppData\Local\{47C613AD-D7AD-41CA-B28D-7BAE879DC7E7}
2011-06-03 16:22 . 2011-04-01 21:07 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-03 16:22 . 2011-04-01 21:07 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-06-03 16:22 . 2011-06-03 16:22 -------- d-----w- c:\programdata\Avira
2011-06-03 16:22 . 2011-06-03 16:22 -------- d-----w- c:\program files (x86)\Avira
2011-06-03 16:07 . 2011-05-09 22:00 8718160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1B5AFB27-65F2-4991-9128-B4545837DD54}\mpengine.dll
2011-06-03 16:01 . 2011-06-03 16:01 -------- d-----w- c:\users\lqi\AppData\Local\{86012517-AA7B-47DA-BF15-62511678C91F}
2011-06-02 15:48 . 2011-06-02 15:48 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-06-02 14:51 . 2011-06-02 14:51 -------- d-sh--w- c:\programdata\PSRAYUJG
2011-06-02 14:51 . 2011-06-02 16:39 -------- d-sh--w- c:\programdata\9c9680
2011-06-02 14:08 . 2011-06-02 14:09 -------- d-----w- c:\users\lqi\AppData\Local\{F05907DF-7EDD-4423-856A-D0FF4380B98B}
2011-06-01 22:33 . 2011-06-01 22:33 -------- d-----w- c:\users\lqi\AppData\Local\{2599A179-C367-462C-9D09-C9BE144C6151}
2011-05-31 21:54 . 2011-05-31 21:55 -------- d-----w- c:\users\lqi\AppData\Local\{44B609B0-D76B-496D-AC23-F2683C36463E}
2011-05-31 14:27 . 2011-05-31 14:27 -------- d-----w- c:\users\lqi\AppData\Local\{30974079-FCC4-4FEB-A28C-6686553205B4}
2011-05-29 17:32 . 2011-05-29 17:32 -------- d-----w- c:\users\lqi\AppData\Local\{22AB9743-4382-4C46-9A18-DB1103E2C332}
2011-05-28 17:43 . 2011-05-28 17:43 -------- d-----w- c:\users\lqi\AppData\Local\{3D83FBD6-96BA-49FE-90F2-57E21AED61F2}
2011-05-27 21:03 . 2011-05-27 21:03 -------- d-----w- c:\users\lqi\AppData\Local\{6027B214-2254-41E9-BA0C-27EDBB51444D}
2011-05-26 18:59 . 2011-05-26 18:59 -------- d-----w- c:\users\lqi\AppData\Local\{7FACE21B-7B07-4C40-9A7A-769005C6C280}
2011-05-26 13:47 . 2011-05-26 13:47 -------- d-----w- c:\users\lqi\AppData\Local\{B5227B09-562F-4738-AB91-BCCFDAF356E0}
2011-05-23 19:23 . 2011-05-23 19:23 -------- d-----w- c:\users\lqi\AppData\Local\{1C35662B-EB08-4FC4-B5C9-ACC7E4CD37DB}
2011-05-21 18:23 . 2011-05-21 18:23 -------- d-----w- c:\users\lqi\AppData\Local\{70D9CF81-81CF-4274-9FCE-9B1C41CED19F}
2011-05-20 15:44 . 2011-05-20 15:44 -------- d-----w- c:\users\lqi\AppData\Local\{71BFEB9D-7CE7-4F25-80D1-1E9647F96F97}
2011-05-19 04:15 . 2011-05-19 04:15 -------- d-----w- c:\users\lqi\AppData\Local\{D5BF2E1A-A18A-4EC2-808C-1AE2298F7700}
2011-05-18 15:09 . 2011-05-18 15:09 -------- d-----w- c:\users\lqi\AppData\Local\{F9116545-AC47-47C7-8346-7E6E6772E2F6}
2011-05-17 22:01 . 2011-05-17 22:02 -------- d-----w- c:\users\lqi\AppData\Local\{846E8560-EBDA-41B6-AEDE-604BD85E5DBC}
2011-05-17 03:12 . 2011-05-17 03:12 -------- d-----w- c:\users\lqi\AppData\Local\{DD24F0E7-5723-4A8E-9052-A220A2931623}
2011-05-16 15:11 . 2011-05-16 15:11 -------- d-----w- c:\users\lqi\AppData\Local\{9FB0004E-AFAE-43E5-8351-63728D73657D}
2011-05-15 16:41 . 2011-05-15 16:41 -------- d-----w- c:\users\lqi\AppData\Local\{07055C99-2753-4360-95E7-B07ED4C70AC7}
2011-05-15 03:44 . 2011-05-15 03:44 -------- d-----w- c:\users\lqi\AppData\Local\{2D540C3C-8AEF-4377-AFB5-B39572D605C2}
2011-05-12 21:47 . 2011-05-12 21:48 -------- d-----w- c:\users\lqi\AppData\Local\{73D5611E-8E72-4620-9274-F4D5B6F198CE}
2011-05-12 00:31 . 2011-04-07 12:01 2409784 ----a-w- c:\program files (x86)\Windows Mail\OESpamFilter.dat
2011-05-12 00:31 . 2011-04-07 12:02 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-05-12 00:17 . 2011-05-12 00:17 -------- d-----w- c:\users\lqi\AppData\Local\{DFD6E4D3-1B0D-4377-9CBB-E7F2087EDD6B}
2011-05-10 02:04 . 2011-05-10 02:04 -------- d-----w- c:\users\lqi\AppData\Local\{7E60F79F-2C5A-4799-AECA-3ED34246ED6A}
2011-05-09 23:17 . 2011-05-09 23:17 -------- d-----w- c:\users\lqi\AppData\Local\{84E3A561-CA30-4323-B7AF-D0CAF3217DEF}
2011-05-07 14:54 . 2011-05-07 14:54 -------- d-----w- c:\users\lqi\AppData\Local\{DE6A09E6-6A1F-46F7-BC63-EAB0EFE6FA58}
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2011-05-29 13:11 . 2010-08-05 06:44 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-06 20:26 . 2011-04-06 20:26 96544 ----a-w- c:\windows\system32\dnssd.dll
2011-04-06 20:26 . 2011-04-06 20:26 237856 ----a-w- c:\windows\system32\dnssdX.dll
2011-04-06 20:26 . 2011-04-06 20:26 119584 ----a-w- c:\windows\system32\dns-sd.exe
2011-04-06 20:20 . 2011-04-06 20:20 91424 ----a-w- c:\windows\SysWow64\dnssd.dll
2011-04-06 20:20 . 2011-04-06 20:20 197920 ----a-w- c:\windows\SysWow64\dnssdX.dll
2011-04-06 20:20 . 2011-04-06 20:20 107808 ----a-w- c:\windows\SysWow64\dns-sd.exe
2011-03-12 22:52 . 2011-04-28 14:12 1653760 ----a-w- c:\windows\system32\XpsPrint.dll
2011-03-12 21:55 . 2011-04-28 14:12 876032 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2011-03-11 19:32 . 2010-06-24 15:33 18328 ------w- c:\programdata\Microsoft\IdentityCRL\production\pp crlconfig600.dll
2011-03-10 17:18 . 2011-04-15 22:04 1360384 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-10 17:18 . 2011-04-15 22:04 1398784 ----a-w- c:\windows\system32\mfc42.dll
2011-03-10 17:03 . 2011-04-15 22:04 1162240 ----a-w- c:\windows\SysWow64\mfc42u.dll
2011-03-10 17:03 . 2011-04-15 22:04 1136640 ----a-w- c:\windows\SysWow64\mfc42.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968]
"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760]
"Messenger (Yahoo!)"="c:\progra~2\Yahoo!\Messenger\YahooMesse nger.exe" [2010-06-01 5252408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\ Windows\CurrentVersion\Run]
"TPFNF7"="c:\program files (x86)\Lenovo\NPDIRECT\TPFNF7SP.exe" [2009-04-15 61728]
"EZEJMNAP"="c:\progra~2\ThinkPad\UTILIT~1\EzEjMnAp .Exe" [2008-10-07 256576]
"TVT Scheduler Proxy"="c:\program files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-05-24 487424]
"LPManager"="c:\progra~2\THINKV~1\PrdCtr\LPMGR.exe " [2008-08-31 165208]
"LPMailChecker"="c:\progra~2\THINKV~1\PrdCtr\LPMLC HK.exe" [2008-08-31 124248]
"AMSG"="c:\program files (x86)\ThinkVantage\AMSG\Amsg.exe" [2009-03-19 461376]
"CameraApplicationLauncher"="c:\program files (x86)\Lenovo\Camera Center\bin\CameraApplicationLaunchpadLauncher.exe" [2009-03-13 16384]
"RoxioDragToDisc"="c:\program files (x86)\Lenovo2\Drag-to-Disc\DrgToDsc.exe" [2008-08-12 1116656]
"PWMTRV"="c:\progra~2\ThinkPad\UTILIT~1\PWMTR64V.D LL" [2009-01-14 796448]
"BLOG"="c:\progra~2\ThinkPad\UTILIT~1\BTVLogEx.DLL " [2009-01-14 214576]
"CreateLMBCShortCut"="c:\program files (x86)\Lenovo\Mobile Broadband Connect\UserShortcutCreator.exe" [2009-05-15 40960]
"ACTray"="c:\program files (x86)\ThinkPad\ConnectUtilities\ACTray.exe" [2009-07-10 435488]
"ACWlIcon"="c:\program files (x86)\ThinkPad\ConnectUtilities\ACWlIcon.exe" [2009-07-10 177440]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2011-01-31 38840]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2010-09-22 640440]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"CarboniteSetupLite"="c:\program files (x86)\Carbonite\CarbonitePreinstaller.exe" [2009-08-04 318096]
"MaxMenuMgr"="c:\program files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-26 185640]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-03-28 281768]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-04-27 421160]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files (x86)\Digital Line Detect\DLG.exe [2009-8-5 50688]
RCIMGDIR.exe.lnk - c:\program files (x86)\RotateImage\RCIMGDIR.exe [2009-8-5 55296]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\ windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R1 tvtumon;tvtumon;c:\windows\system32\DRIVERS\tvtumo n.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\ v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework6 4\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2009-05-21 45424]
R2 TVT_UpdateMonitor;TVT Windows Update Monitor;c:\program files (x86)\Lenovo\Rescue and Recovery\UpdateMonitor.exe [2008-10-09 360448]
R2 WebUpdate4;Web Update Wizard Service V4;c:\windows\SysWOW64\WebUpdateSvc4.exe [x]
R3 ICDUSB3;ICDUSB3;c:\windows\system32\Drivers\ICDUSB 3.sys [x]
R3 MosIrUsb;MosIrUsb.sys;c:\windows\system32\DRIVERS\ MosIrUsb.sys [x]
R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys [x]
R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRI VERS\motccgpfl.sys [x]
R3 MUXP;My WiFi PAN Mux-IM Protocol Driver;c:\windows\system32\DRIVERS\mux.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2009-02-11 306688]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [x]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2008-04-25 1120752]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0. 30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
S0 DRVECDB;DRVECDB;c:\windows\System32\Drivers\DRVECD B.SYS [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHl pa64.sys [x]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsH M64.sys [x]
S1 DLACDBHE;DLACDBHE;c:\windows\system32\Drivers\DLAC DBHE.SYS [x]
S1 DLARTL_E;DLARTL_E;c:\windows\system32\Drivers\DLAR TL_E.SYS [x]
S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiifx64.sys [x]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-03-28 136360]
S2 DLABMFSE;DLABMFSE;c:\windows\system32\DLA\DLABMFSE .SYS [x]
S2 DLABOIOE;DLABOIOE;c:\windows\system32\DLA\DLABOIOE .SYS [x]
S2 DLADResE;DLADResE;c:\windows\system32\DLA\DLADResE .SYS [x]
S2 DLAIFS_E;DLAIFS_E;c:\windows\system32\DLA\DLAIFS_E .SYS [x]
S2 DLAOPIOE;DLAOPIOE;c:\windows\system32\DLA\DLAOPIOE .SYS [x]
S2 DLAPoolE;DLAPoolE;c:\windows\system32\DLA\DLAPoolE .SYS [x]
S2 DLAUDF_E;DLAUDF_E;c:\windows\system32\DLA\DLAUDF_E .SYS [x]
S2 DLAUDFAE;DLAUDFAE;c:\windows\system32\DLA\DLAUDFAE .SYS [x]
S2 DRVEDDM;DRVEDDM;c:\windows\system32\Drivers\DRVEDD M.SYS [x]
S2 FreeAgentGoNext Service;Seagate Service;c:\program files (x86)\Seagate\SeagateManager\Sync\FreeAgentService .exe [2009-09-26 189736]
S2 Power Manager DBC Service;Power Manager DBC Service;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2009-01-14 66848]
S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2009-05-21 62320]
S2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files (x86)\Lenovo\Rescue and Recovery\rrpservice.exe [2008-05-24 520192]
S2 UNS;Intel(R) Active Management Technology User Notification Service;c:\program files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2008-05-29 2058776]
S3 5U875UVC;Integrated Camera;c:\windows\system32\DRIVERS\5U875.sys [x]
S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXH WAZL.sys [x]
S3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 MUXMP;My WiFi PAN MUX-IM Virtual Miniport Driver;c:\windows\system32\DRIVERS\mux.sys [x]
S3 NETw5v64;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 64 Bit ;c:\windows\system32\DRIVERS\NETw5v64.sys [x]
S3 Tp4Track;PS/2 TrackPoint Driver;c:\windows\system32\DRIVERS\tp4track.sys [x]
S3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\DRIVERS\Tvti2c.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2010-12-14 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\PCDR5\pcdr5cuiw32.exe [2009-02-20 21:00]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"combofix"="c:\combofix\CF17847.cfxxe" [X]
"TrackPointSrv"="c:\program files\Lenovo\TrackPoint\tp4serv.exe" [2009-01-26 135968]
"picon"="c:\program files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" [2008-11-13 357400]
"TpShocks"="TpShocks.exe" [2009-02-03 228640]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2009-02-11 1914880]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2009-03-13 68976]
"LENOVO.TPFNF6R"="c:\program files\Lenovo\HOTKEY\TPFNF6R.exe" [2009-04-14 15136]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-09-17 151064]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-09-17 209432]
"Persistence"="c:\windows\system32\igfxpers.ex e" [2008-09-17 180560]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-05 170496]
"cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2008-06-25 7253304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\acaptuser64 .dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.yahoo.com
uDefault_Search_URL = hxxp://www.google.com/ie
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 68.87.68.166 68.87.74.166
TCP: Interfaces\{395AFEDA-7FBE-45D7-959C-3C3D7D883C12}: NameServer = 0.0.0.0
DPF: {AC414988-E5BB-4C2C-873B-EA53D2F3D23A} - hxxp://t.live.cctv.com/ieocx/CCTVUpdateInstall.dll
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
FF - ProfilePath - c:\users\lqi\AppData\Roaming\Mozilla\Firefox\Profi les\d7tyfmwv.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-Windows Defender - c:\program files (x86)\Windows Defender\MSASCui.exe
AddRemove-Web Update Wizard (Redistributable) - c:\windows\system32\wuwuninst.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macrome d\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUt il10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10 p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10 p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10 p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10 p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\In terface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\In terface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\In terface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Ty peLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Ty peLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Ty peLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Ty peLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00 ,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00 ,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files (x86)\Intel\AMT\LMS.exe
c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\program files (x86)\Lenovo\Client Security Solution\tvttcsd.exe
c:\program files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
c:\program files (x86)\Common Files\Lenovo\Scheduler\tvtsched.exe
c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files (x86)\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files (x86)\Lenovo\System Update\SUService.exe
c:\program files (x86)\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\Lenovo\HOTKEY\TPONSCR.exe
c:\program files\Lenovo\Zoom\TpScrex.exe
c:\program files (x86)\ThinkPad\Utilities\EZEJMNAP.EXE
c:\program files (x86)\ThinkVantage\PrdCtr\LPMGR.EXE
c:\program files (x86)\ThinkVantage\PrdCtr\LPMLCHK.EXE
c:\windows\SysWOW64\rundll32.exe
c:\program files (x86)\Lenovo\Camera Center\bin\LenovoCameraCenter.exe
c:\program files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
c:\progra~2\ThinkPad\UTILIT~1\PWMUIAux.exe
.
************************************************** ************************
.
Completion time: 2011-06-05 13:35:31 - machine was rebooted
ComboFix-quarantined-files.txt 2011-06-05 17:35
.
Pre-Run: 41,751,715,840 bytes free
Post-Run: 41,214,369,792 bytes free
.
- - End Of File - - DC778CDCD34245602F9BB612B543E0E4
Combofix log looks fine now.
How is computer doing?
Download TDSSKiller and save it to your desktop.
- Extract (unzip) its contents to your desktop.
- Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
- If an infected file is detected, the default action will be Cure, click on Continue.
- If a suspicious file is detected, the default action will be Skip, click on Continue.
- It may ask you to reboot the computer to complete the process. Click on Reboot Now.
- If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
- If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
I'll try the TDSSKiller now. So should I select the "remove" option from Avira's message on C:\ComboFix\handle.cfxxe?
Also, Find Gala kept redirecting my google search and this still happens now after the ComboFix run.
Here is the TDSSKiller log results:
2011/06/05 14:05:18.0089 5280 TDSS rootkit removing tool 2.5.3.0 May 25 2011 07:09:24
2011/06/05 14:05:18.0822 5280 ================================================== ==============================
2011/06/05 14:05:18.0822 5280 SystemInfo:
2011/06/05 14:05:18.0822 5280
2011/06/05 14:05:18.0822 5280 OS Version: 6.0.6002 ServicePack: 2.0
2011/06/05 14:05:18.0822 5280 Product type: Workstation
2011/06/05 14:05:18.0822 5280 ComputerName: LQI-PC
2011/06/05 14:05:18.0822 5280 UserName: lqi
2011/06/05 14:05:18.0822 5280 Windows directory: C:\Windows
2011/06/05 14:05:18.0822 5280 System windows directory: C:\Windows
2011/06/05 14:05:18.0822 5280 Running under WOW64
2011/06/05 14:05:18.0822 5280 Processor architecture: Intel x64
2011/06/05 14:05:18.0822 5280 Number of processors: 2
2011/06/05 14:05:18.0822 5280 Page size: 0x1000
2011/06/05 14:05:18.0822 5280 Boot type: Normal boot
2011/06/05 14:05:18.0822 5280 ================================================== ==============================
2011/06/05 14:05:19.0399 5280 Initialize success
2011/06/05 14:05:38.0853 5588 ================================================== ==============================
2011/06/05 14:05:38.0853 5588 Scan started
2011/06/05 14:05:38.0853 5588 Mode: Manual;
2011/06/05 14:05:38.0853 5588 ================================================== ==============================
2011/06/05 14:05:39.0508 5588 5U875UVC (37086eab1d76b8b6d10251c2f5072836) C:\Windows\system32\DRIVERS\5U875.sys
2011/06/05 14:05:39.0648 5588 ACPI (1965aaffab07e3fb03c77f81beba3547) C:\Windows\system32\drivers\acpi.sys
2011/06/05 14:05:39.0851 5588 adp94xx (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys
2011/06/05 14:05:39.0991 5588 adpahci (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys
2011/06/05 14:05:40.0101 5588 adpu160m (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys
2011/06/05 14:05:40.0241 5588 adpu320 (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys
2011/06/05 14:05:40.0381 5588 AFD (12415ccfd3e7cec55b5184e67b039fe4) C:\Windows\system32\drivers\afd.sys
2011/06/05 14:05:40.0537 5588 agp440 (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys
2011/06/05 14:05:40.0615 5588 aic78xx (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys
2011/06/05 14:05:40.0709 5588 aliide (f47743e97b2f4de6913038d7b14e7dd0) C:\Windows\system32\drivers\aliide.sys
2011/06/05 14:05:40.0756 5588 amdide (695b3ea14709aa794ca6d13d5437d399) C:\Windows\system32\drivers\amdide.sys
2011/06/05 14:05:40.0818 5588 AmdK8 (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys
2011/06/05 14:05:41.0021 5588 arc (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys
2011/06/05 14:05:41.0099 5588 arcsas (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys
2011/06/05 14:05:41.0177 5588 AsyncMac (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/06/05 14:05:41.0239 5588 atapi (e68d9b3a3905619732f7fe039466a623) C:\Windows\system32\drivers\atapi.sys
2011/06/05 14:05:41.0317 5588 avgntflt (39c2e2870fc0c2ae0595b883cbe716b4) C:\Windows\system32\DRIVERS\avgntflt.sys
2011/06/05 14:05:41.0380 5588 avipbb (c98fa6e5ad0e857d22716bd2b8b1f399) C:\Windows\system32\DRIVERS\avipbb.sys
2011/06/05 14:05:41.0536 5588 blbdrive (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys
2011/06/05 14:05:41.0629 5588 bowser (2348447a80920b2493a9b582a23e81e1) C:\Windows\system32\DRIVERS\bowser.sys
2011/06/05 14:05:41.0723 5588 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys
2011/06/05 14:05:41.0770 5588 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys
2011/06/05 14:05:41.0848 5588 Brserid (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys
2011/06/05 14:05:41.0879 5588 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys
2011/06/05 14:05:41.0941 5588 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys
2011/06/05 14:05:42.0004 5588 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys
2011/06/05 14:05:42.0066 5588 BTHMODEM (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys
2011/06/05 14:05:42.0191 5588 CAXHWAZL (cd69e6640bc4778eb4159d34a707106e) C:\Windows\system32\DRIVERS\CAXHWAZL.sys
2011/06/05 14:05:42.0269 5588 cdfs (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys
2011/06/05 14:05:42.0347 5588 cdrom (c025aa69be3d0d25c7a2e746ef6f94fc) C:\Windows\system32\DRIVERS\cdrom.sys
2011/06/05 14:05:42.0425 5588 circlass (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\drivers\circlass.sys
2011/06/05 14:05:42.0503 5588 CLFS (3dca9a18b204939cfb24bea53e31eb48) C:\Windows\system32\CLFS.sys
2011/06/05 14:05:42.0643 5588 CmBatt (b52d9a14ce4101577900a364ba86f3df) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/06/05 14:05:42.0675 5588 cmdide (7f1f812ac7adbead711d131f17c8ed77) C:\Windows\system32\drivers\cmdide.sys
2011/06/05 14:05:42.0768 5588 CnxtHdAudService (b921e4b6483f225755d0e48654f7081f) C:\Windows\system32\drivers\CHDRT64.sys
2011/06/05 14:05:42.0846 5588 Compbatt (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\DRIVERS\compbatt.sys
2011/06/05 14:05:42.0909 5588 crcdisk (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys
2011/06/05 14:05:43.0018 5588 CSC (f60f50c8ed3fcbe358430b95fe27d09c) C:\Windows\system32\drivers\csc.sys
2011/06/05 14:05:43.0127 5588 DfsC (36cd31121f228e7e79bae60aa45764c6) C:\Windows\system32\Drivers\dfsc.sys
2011/06/05 14:05:43.0267 5588 disk (b0107e40ecdb5fa692ebf832f295d905) C:\Windows\system32\drivers\disk.sys
2011/06/05 14:05:43.0377 5588 DLABMFSE (c27713c1fc7c238d5021919d0011bc73) C:\Windows\system32\DLA\DLABMFSE.SYS
2011/06/05 14:05:43.0423 5588 DLABOIOE (fb678e1538dd4fa4eacde8ea2e6d23f5) C:\Windows\system32\DLA\DLABOIOE.SYS
2011/06/05 14:05:43.0455 5588 DLACDBHE (8bffdf668b5b3db82b45fd98f6d5b047) C:\Windows\system32\Drivers\DLACDBHE.SYS
2011/06/05 14:05:43.0486 5588 DLADResE (b8fc01714306cdced91f4c8e8a5f9959) C:\Windows\system32\DLA\DLADResE.SYS
2011/06/05 14:05:43.0517 5588 DLAIFS_E (a21ca4b265f02df355b23d1880a47b0a) C:\Windows\system32\DLA\DLAIFS_E.SYS
2011/06/05 14:05:43.0548 5588 DLAOPIOE (0473e600175aaa7a94f7105bd51501d5) C:\Windows\system32\DLA\DLAOPIOE.SYS
2011/06/05 14:05:43.0579 5588 DLAPoolE (926a191652c52f8c29945d4fbcc342f3) C:\Windows\system32\DLA\DLAPoolE.SYS
2011/06/05 14:05:43.0642 5588 DLARTL_E (c8129d9fcd1e8d24beaa0a65a8e70c40) C:\Windows\system32\Drivers\DLARTL_E.SYS
2011/06/05 14:05:43.0673 5588 DLAUDFAE (85dbe7478171b973d3a485cbc8aa5a8a) C:\Windows\system32\DLA\DLAUDFAE.SYS
2011/06/05 14:05:43.0704 5588 DLAUDF_E (27dca215bb399ea472b4277664aebd8c) C:\Windows\system32\DLA\DLAUDF_E.SYS
2011/06/05 14:05:43.0798 5588 dot4 (74c02b1717740c3b8039539e23e4b53f) C:\Windows\system32\DRIVERS\Dot4.sys
2011/06/05 14:05:43.0829 5588 Dot4Print (08321d1860235bf42cf2854234337aea) C:\Windows\system32\DRIVERS\Dot4Prt.sys
2011/06/05 14:05:43.0860 5588 dot4usb (4adccf0124f2b6911d3786a5d0e779e5) C:\Windows\system32\DRIVERS\dot4usb.sys
2011/06/05 14:05:43.0969 5588 drmkaud (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys
2011/06/05 14:05:44.0016 5588 DRVECDB (401b92f84c65b05302a2c0b29c7a40f1) C:\Windows\system32\Drivers\DRVECDB.SYS
2011/06/05 14:05:44.0032 5588 DRVEDDM (20c296250f155e60b16a3b4601d28695) C:\Windows\system32\Drivers\DRVEDDM.SYS
2011/06/05 14:05:44.0110 5588 DXGKrnl (b8e554e502d5123bc111f99d6a2181b4) C:\Windows\System32\drivers\dxgkrnl.sys
2011/06/05 14:05:44.0203 5588 e1express (17d40652ef3e55eeae187a89df40965a) C:\Windows\system32\DRIVERS\e1e6032e.sys
2011/06/05 14:05:44.0281 5588 E1G60 (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys
2011/06/05 14:05:44.0391 5588 e1yexpress (d608110adb132e683360fca0f6b2bb53) C:\Windows\system32\DRIVERS\e1y60x64.sys
2011/06/05 14:05:44.0500 5588 Ecache (5f94962be5a62db6e447ff6470c4f48a) C:\Windows\system32\drivers\ecache.sys
2011/06/05 14:05:44.0547 5588 elxstor (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys
2011/06/05 14:05:44.0609 5588 ErrDev (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys
2011/06/05 14:05:44.0718 5588 exfat (486844f47b6636044a42454614ed4523) C:\Windows\system32\drivers\exfat.sys
2011/06/05 14:05:44.0749 5588 fastfat (1a4bee34277784619ddaf0422c0c6e23) C:\Windows\system32\drivers\fastfat.sys
2011/06/05 14:05:44.0827 5588 fdc (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys
2011/06/05 14:05:44.0859 5588 FileInfo (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys
2011/06/05 14:05:44.0890 5588 Filetrace (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys
2011/06/05 14:05:44.0968 5588 flpydisk (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/06/05 14:05:45.0015 5588 FltMgr (e3041bc26d6930d61f42aedb79c91720) C:\Windows\system32\drivers\fltmgr.sys
2011/06/05 14:05:45.0124 5588 Fs_Rec (29d99e860a1ca0a03c6a733fdd0da703) C:\Windows\system32\drivers\Fs_Rec.sys
2011/06/05 14:05:45.0186 5588 gagp30kx (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys
2011/06/05 14:05:45.0280 5588 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2011/06/05 14:05:45.0373 5588 HdAudAddService (df45f8142dc6df9d18c39b3effbd0409) C:\Windows\system32\drivers\HdAudio.sys
2011/06/05 14:05:45.0451 5588 HDAudBus (f942c5820205f2fb453243edfec82a3d) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/06/05 14:05:45.0561 5588 HECIx64 (c936f49f1da1f4cc9eebcd805abc2bba) C:\Windows\system32\DRIVERS\HECIx64.sys
2011/06/05 14:05:45.0607 5588 HidBth (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys
2011/06/05 14:05:45.0639 5588 HidIr (4e77a77e2c986e8f88f996bb3e1ad829) C:\Windows\system32\drivers\hidir.sys
2011/06/05 14:05:45.0732 5588 HidUsb (443bdd2d30bb4f00795c797e2cf99edf) C:\Windows\system32\DRIVERS\hidusb.sys
2011/06/05 14:05:45.0810 5588 HpCISSs (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys
2011/06/05 14:05:45.0888 5588 HSFHWAZL (57ba73b5b321291e5114cb21350e1ea0) C:\Windows\system32\DRIVERS\VSTAZL6.SYS
2011/06/05 14:05:45.0982 5588 HSF_DPV (ebdba99c2362457be429f024396b63be) C:\Windows\system32\DRIVERS\CAX_DPV.sys
2011/06/05 14:05:46.0091 5588 HTTP (098f1e4e5c9cb5b0063a959063631610) C:\Windows\system32\drivers\HTTP.sys
2011/06/05 14:05:46.0185 5588 i2omp (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys
2011/06/05 14:05:46.0247 5588 i8042prt (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/06/05 14:05:46.0341 5588 iaStor (1adaa4f16073fd0c7270f451fd024e97) C:\Windows\system32\DRIVERS\iaStor.sys
2011/06/05 14:05:46.0372 5588 iaStorV (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys
2011/06/05 14:05:46.0434 5588 IBMPMDRV (287c219b595dc73f2fcdc0e9d172c711) C:\Windows\system32\DRIVERS\ibmpmdrv.sys
2011/06/05 14:05:46.0497 5588 ICDUSB3 (55836a07c030748b47c613dc30f724d5) C:\Windows\system32\Drivers\ICDUSB3.sys
2011/06/05 14:05:46.0777 5588 igfx (ea58016577eac334f9eb402bfbdfb740) C:\Windows\system32\DRIVERS\igdkmd64.sys
2011/06/05 14:05:47.0058 5588 iirsp (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys
2011/06/05 14:05:47.0105 5588 intelide (c26e78eb76be83a8568ceb964cd64111) C:\Windows\system32\drivers\intelide.sys
2011/06/05 14:05:47.0136 5588 intelppm (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys
2011/06/05 14:05:47.0199 5588 IpFilterDriver (d8aabc341311e4780d6fce8c73c0ad81) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/06/05 14:05:47.0292 5588 IPMIDRV (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys
2011/06/05 14:05:47.0339 5588 IPNAT (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys
2011/06/05 14:05:47.0417 5588 irda (86583188c7157ffda249529423fc3e6f) C:\Windows\system32\DRIVERS\irda.sys
2011/06/05 14:05:47.0448 5588 IRENUM (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys
2011/06/05 14:05:47.0542 5588 isapnp (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys
2011/06/05 14:05:47.0620 5588 iScsiPrt (e4fdf99599f27ec25d2cf6d754243520) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/06/05 14:05:47.0667 5588 iteatapi (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys
2011/06/05 14:05:47.0745 5588 iteraid (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys
2011/06/05 14:05:47.0807 5588 kbdclass (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/06/05 14:05:47.0854 5588 kbdhid (dbdf75d51464fbc47d0104ec3d572c05) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/06/05 14:05:47.0947 5588 KSecDD (476e2c1dcea45895994bef11c2a98715) C:\Windows\system32\Drivers\ksecdd.sys
2011/06/05 14:05:48.0010 5588 ksthunk (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys
2011/06/05 14:05:48.0119 5588 lenovo.smi (5acff5823634bc2c4ebf559c3b33e18e) C:\Windows\system32\DRIVERS\smiifx64.sys
2011/06/05 14:05:48.0150 5588 lltdio (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys
2011/06/05 14:05:48.0213 5588 LSI_FC (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys
2011/06/05 14:05:48.0291 5588 LSI_SAS (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys
2011/06/05 14:05:48.0322 5588 LSI_SCSI (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys
2011/06/05 14:05:48.0353 5588 luafv (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys
2011/06/05 14:05:48.0400 5588 mdmxsdk (e4f44ec214b3e381e1fc844a02926666) C:\Windows\system32\DRIVERS\mdmxsdk.sys
2011/06/05 14:05:48.0478 5588 megasas (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys
2011/06/05 14:05:48.0571 5588 MegaSR (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys
2011/06/05 14:05:48.0634 5588 Modem (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys
2011/06/05 14:05:48.0712 5588 monitor (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys
2011/06/05 14:05:48.0774 5588 MosIrUsb (54f44c3a4f6c1c4d00d4157fbd531eb1) C:\Windows\system32\DRIVERS\MosIrUsb.sys
2011/06/05 14:05:48.0821 5588 motccgp (7bd101253058db30c52c6ea8d3911754) C:\Windows\system32\DRIVERS\motccgp.sys
2011/06/05 14:05:48.0852 5588 motccgpfl (1a700e7063ca7f2b29a4e761da604dfb) C:\Windows\system32\DRIVERS\motccgpfl.sys
2011/06/05 14:05:48.0899 5588 mouclass (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys
2011/06/05 14:05:48.0977 5588 mouhid (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys
2011/06/05 14:05:49.0008 5588 MountMgr (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys
2011/06/05 14:05:49.0039 5588 mpio (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys
2011/06/05 14:05:49.0086 5588 mpsdrv (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys
2011/06/05 14:05:49.0133 5588 Mraid35x (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys
2011/06/05 14:05:49.0180 5588 MRxDAV (7c1de4aa96dc0c071611f9e7de02a68d) C:\Windows\system32\drivers\mrxdav.sys
2011/06/05 14:05:49.0305 5588 mrxsmb (dc434b4769e18da09ce1b7755d4c64e9) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/06/05 14:05:49.0367 5588 mrxsmb10 (64713fcfe3de8881d62f8f3f2f794241) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/06/05 14:05:49.0445 5588 mrxsmb20 (0005c599a2abf767a815afcd32e523e3) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/06/05 14:05:49.0554 5588 msahci (e7136685c4e3acdb3b9d87ca23e03947) C:\Windows\system32\drivers\msahci.sys
2011/06/05 14:05:49.0585 5588 msdsm (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys
2011/06/05 14:05:49.0632 5588 Msfs (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys
2011/06/05 14:05:49.0710 5588 msisadrv (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys
2011/06/05 14:05:49.0819 5588 MSKSSRV (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys
2011/06/05 14:05:49.0835 5588 MSPCLOCK (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/06/05 14:05:49.0882 5588 MSPQM (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys
2011/06/05 14:05:49.0944 5588 MsRPC (dc6ccf440cdede4293db41c37a5060a5) C:\Windows\system32\drivers\MsRPC.sys
2011/06/05 14:05:50.0007 5588 mssmbios (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/06/05 14:05:50.0085 5588 MSTEE (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys
2011/06/05 14:05:50.0131 5588 Mup (0cc49f78d8aca0877d885f149084e543) C:\Windows\system32\Drivers\mup.sys
2011/06/05 14:05:50.0209 5588 MUXMP (95027ec510ae3e67c4ab103ae544737e) C:\Windows\system32\DRIVERS\mux.sys
2011/06/05 14:05:50.0256 5588 MUXP (95027ec510ae3e67c4ab103ae544737e) C:\Windows\system32\DRIVERS\mux.sys
2011/06/05 14:05:50.0365 5588 NativeWifiP (2007b826c4acd94ae32232b41f0842b9) C:\Windows\system32\DRIVERS\nwifi.sys
2011/06/05 14:05:50.0459 5588 NDIS (65950e07329fcee8e6516b17c8d0abb6) C:\Windows\system32\drivers\ndis.sys
2011/06/05 14:05:50.0521 5588 NdisTapi (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/06/05 14:05:50.0553 5588 Ndisuio (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/06/05 14:05:50.0584 5588 NdisWan (f8158771905260982ce724076419ef19) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/06/05 14:05:50.0615 5588 NDProxy (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys
2011/06/05 14:05:50.0662 5588 NetBIOS (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys
2011/06/05 14:05:50.0693 5588 netbt (fc2c792ebddc8e28df939d6a92c83d61) C:\Windows\system32\DRIVERS\netbt.sys
2011/06/05 14:05:50.0865 5588 NETw5v64 (4b953e6cb07830ff4e236e02cc264d4c) C:\Windows\system32\DRIVERS\NETw5v64.sys
2011/06/05 14:05:51.0099 5588 nfrd960 (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys
2011/06/05 14:05:51.0161 5588 Npfs (b298874f8e0ea93f06ec40aa8d146478) C:\Windows\system32\drivers\Npfs.sys
2011/06/05 14:05:51.0177 5588 nsiproxy (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys
2011/06/05 14:05:51.0286 5588 Ntfs (bac869dfb98e499ba4d9bb1fb43270e1) C:\Windows\system32\drivers\Ntfs.sys
2011/06/05 14:05:51.0411 5588 Null (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys
2011/06/05 14:05:51.0457 5588 nvraid (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys
2011/06/05 14:05:51.0489 5588 nvstor (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys
2011/06/05 14:05:51.0520 5588 nv_agp (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys
2011/06/05 14:05:51.0645 5588 ohci1394 (1b30103fde512915a9214b108b6e7a9c) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/06/05 14:05:51.0707 5588 Parport (aecd57f94c887f58919f307c35498ea0) C:\Windows\system32\drivers\parport.sys
2011/06/05 14:05:51.0754 5588 partmgr (f9b5eda4c17a2be7663f064dbf0fe254) C:\Windows\system32\drivers\partmgr.sys
2011/06/05 14:05:51.0816 5588 pci (47ab1e0fc9d0e12bb53ba246e3a0906d) C:\Windows\system32\drivers\pci.sys
2011/06/05 14:05:51.0894 5588 pciide (2657f6c0b78c36d95034be109336e382) C:\Windows\system32\drivers\pciide.sys
2011/06/05 14:05:51.0972 5588 pcmcia (a2d6b9c3f532baa27cb0c158d8ef4da6) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/06/05 14:05:52.0035 5588 PEAUTH (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys
2011/06/05 14:05:52.0222 5588 PptpMiniport (23386e9952025f5f21c368971e2e7301) C:\Windows\system32\DRIVERS\raspptp.sys
2011/06/05 14:05:52.0315 5588 Processor (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\drivers\processr.sys
2011/06/05 14:05:52.0409 5588 psadd (6b99a6e750c113cfbe766769c4ce7227) C:\Windows\system32\DRIVERS\psadd.sys
2011/06/05 14:05:52.0456 5588 PSched (c5ab7f0809392d0da027f4a2a81bfa31) C:\Windows\system32\DRIVERS\pacer.sys
2011/06/05 14:05:52.0534 5588 PSI (b490d659791ab9dd83328541ebc4ef33) C:\Windows\system32\DRIVERS\psi_mf.sys
2011/06/05 14:05:52.0596 5588 PxHlpa64 (fbf4db6d53585437e41a113300002a2b) C:\Windows\system32\Drivers\PxHlpa64.sys
2011/06/05 14:05:52.0659 5588 ql2300 (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys
2011/06/05 14:05:52.0737 5588 ql40xx (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys
2011/06/05 14:05:52.0783 5588 QWAVEdrv (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys
2011/06/05 14:05:52.0815 5588 RasAcd (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys
2011/06/05 14:05:52.0861 5588 Rasl2tp (ac7bc4d42a7e558718dfdec599bbfc2c) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/06/05 14:05:52.0924 5588 RasPppoe (4517fbf8b42524afe4ede1de102aae3e) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/06/05 14:05:52.0955 5588 RasSstp (c6a593b51f34c33e5474539544072527) C:\Windows\system32\DRIVERS\rassstp.sys
2011/06/05 14:05:52.0986 5588 rdbss (322db5c6b55e8d8ee8d6f358b2aaabb1) C:\Windows\system32\DRIVERS\rdbss.sys
2011/06/05 14:05:53.0033 5588 RDPCDD (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/06/05 14:05:53.0095 5588 rdpdr (ae23e79b13feb62939e2ca1189e71735) C:\Windows\system32\DRIVERS\rdpdr.sys
2011/06/05 14:05:53.0127 5588 RDPENCDD (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys
2011/06/05 14:05:53.0189 5588 RDPWD (b1d741c87cea8d7282146366cc9c3f81) C:\Windows\system32\drivers\RDPWD.sys
2011/06/05 14:05:53.0267 5588 rspndr (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys
2011/06/05 14:05:53.0298 5588 sbp2port (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys
2011/06/05 14:05:53.0345 5588 sdbus (b42ee50f7d24f837f925332eb349eca5) C:\Windows\system32\DRIVERS\sdbus.sys
2011/06/05 14:05:53.0376 5588 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
2011/06/05 14:05:53.0407 5588 Serenum (f71bfe7ac6c52273b7c82cbf1bb2a222) C:\Windows\system32\DRIVERS\serenum.sys
2011/06/05 14:05:53.0439 5588 Serial (e62fac91ee288db29a9696a9d279929c) C:\Windows\system32\DRIVERS\serial.sys
2011/06/05 14:05:53.0470 5588 sermouse (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys
2011/06/05 14:05:53.0517 5588 sffdisk (14d4b4465193a87c127933978e8c4106) C:\Windows\system32\drivers\sffdisk.sys
2011/06/05 14:05:53.0548 5588 sffp_mmc (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys
2011/06/05 14:05:53.0563 5588 sffp_sd (35e59ebe4a01a0532ed67975161c7b82) C:\Windows\system32\drivers\sffp_sd.sys
2011/06/05 14:05:53.0610 5588 sfloppy (40567781f0785c4a69411d1b40da8987) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/06/05 14:05:53.0719 5588 Shockprf (e3b2d8fb86c3d92a2832b8e196f105da) C:\Windows\system32\DRIVERS\Apsx64.sys
2011/06/05 14:05:53.0751 5588 SiSRaid2 (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys
2011/06/05 14:05:53.0782 5588 SiSRaid4 (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys
2011/06/05 14:05:53.0829 5588 Smb (290b6f6a0ec4fcdfc90f5cb6d7020473) C:\Windows\system32\DRIVERS\smb.sys
2011/06/05 14:05:53.0891 5588 spldr (386c3c63f00a7040c7ec5e384217e89d) C:\Windows\system32\drivers\spldr.sys
2011/06/05 14:05:53.0969 5588 srv (880a57fccb571ebd063d4dd50e93e46d) C:\Windows\system32\DRIVERS\srv.sys
2011/06/05 14:05:54.0031 5588 srv2 (fa36d119249bf27bc4c0079734e1f33b) C:\Windows\system32\DRIVERS\srv2.sys
2011/06/05 14:05:54.0078 5588 srvnet (cfe7bc92d52c7e79427545909a0182f8) C:\Windows\system32\DRIVERS\srvnet.sys
2011/06/05 14:05:54.0219 5588 swenum (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys
2011/06/05 14:05:54.0250 5588 Symc8xx (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys
2011/06/05 14:05:54.0297 5588 Sym_hi (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys
2011/06/05 14:05:54.0343 5588 Sym_u3 (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys
2011/06/05 14:05:54.0468 5588 Tcpip (973658a2ea9c06b2976884b9046dfc6c) C:\Windows\system32\drivers\tcpip.sys
2011/06/05 14:05:54.0577 5588 Tcpip6 (973658a2ea9c06b2976884b9046dfc6c) C:\Windows\system32\DRIVERS\tcpip.sys
2011/06/05 14:05:54.0655 5588 tcpipreg (c7e72a4071ee0200e3c075dacfb2b334) C:\Windows\system32\drivers\tcpipreg.sys
2011/06/05 14:05:54.0718 5588 TDPIPE (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys
2011/06/05 14:05:54.0749 5588 TDTCP (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys
2011/06/05 14:05:54.0796 5588 tdx (458919c8c42e398dc4802178d5ffee27) C:\Windows\system32\DRIVERS\tdx.sys
2011/06/05 14:05:54.0858 5588 TermDD (8c19678d22649ec002ef2282eae92f98) C:\Windows\system32\DRIVERS\termdd.sys
2011/06/05 14:05:54.0967 5588 Tp4Track (9272164793d2e1ca0f831f6c472e8e08) C:\Windows\system32\DRIVERS\tp4track.sys
2011/06/05 14:05:55.0030 5588 TPDIGIMN (017de0b5d88c099520f24a355636e19b) C:\Windows\system32\DRIVERS\ApsHM64.sys
2011/06/05 14:05:55.0123 5588 TPM (270308efb59976157755c768b8544b5f) C:\Windows\system32\drivers\tpm.sys
2011/06/05 14:05:55.0186 5588 TPPWRIF (2c067e01d6bbccc88b233b868e210907) C:\Windows\system32\drivers\Tppwr64v.sys
2011/06/05 14:05:55.0233 5588 tssecsrv (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/06/05 14:05:55.0311 5588 tunmp (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys
2011/06/05 14:05:55.0389 5588 tunnel (30a9b3f45ad081bffc3bcaa9c812b609) C:\Windows\system32\DRIVERS\tunnel.sys
2011/06/05 14:05:55.0435 5588 tvtfilter (d66852a1de31fe48959841ed02fd1b92) C:\Windows\system32\DRIVERS\tvtfilter.sys
2011/06/05 14:05:55.0482 5588 TVTI2C (b9aa92bae99d63897cb9de420a40e4e8) C:\Windows\system32\DRIVERS\Tvti2c.sys
2011/06/05 14:05:55.0529 5588 tvtumon (03c3daa6c16dde7bbeae0e46d0315d84) C:\Windows\system32\DRIVERS\tvtumon.sys
2011/06/05 14:05:55.0576 5588 uagp35 (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys
2011/06/05 14:05:55.0623 5588 udfs (faf2640a2a76ed03d449e443194c4c34) C:\Windows\system32\DRIVERS\udfs.sys
2011/06/05 14:05:55.0685 5588 uliagpkx (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys
2011/06/05 14:05:55.0716 5588 uliahci (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys
2011/06/05 14:05:55.0779 5588 UlSata (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys
2011/06/05 14:05:55.0810 5588 ulsata2 (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys
2011/06/05 14:05:55.0857 5588 umbus (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys
2011/06/05 14:05:55.0935 5588 USBAAPL64 (54d4b48d443e7228bf64cf7cdc3118ac) C:\Windows\system32\Drivers\usbaapl64.sys
2011/06/05 14:05:56.0013 5588 usbccgp (07e3498fc60834219d2356293da0fecc) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/06/05 14:05:56.0044 5588 usbcir (9247f7e0b65852c1f6631480984d6ed2) C:\Windows\system32\drivers\usbcir.sys
2011/06/05 14:05:56.0106 5588 usbehci (827e44de934a736ea31e91d353eb126f) C:\Windows\system32\DRIVERS\usbehci.sys
2011/06/05 14:05:56.0137 5588 usbhub (bb35cd80a2ececfadc73569b3d70c7d1) C:\Windows\system32\DRIVERS\usbhub.sys
2011/06/05 14:05:56.0184 5588 usbohci (eba14ef0c07cec233f1529c698d0d154) C:\Windows\system32\drivers\usbohci.sys
2011/06/05 14:05:56.0215 5588 usbprint (acfee697af477021bb3ec78c5431fed2) C:\Windows\system32\drivers\usbprint.sys
2011/06/05 14:05:56.0247 5588 USBSTOR (b854c1558fca0c269a38663e8b59b581) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/06/05 14:05:56.0309 5588 usbuhci (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/06/05 14:05:56.0356 5588 usbvideo (fc33099877790d51b0927b7039059855) C:\Windows\system32\Drivers\usbvideo.sys
2011/06/05 14:05:56.0449 5588 vga (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/06/05 14:05:56.0512 5588 VgaSave (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys
2011/06/05 14:05:56.0574 5588 viaide (e4522279e70facc314d0f3e35da2adab) C:\Windows\system32\drivers\viaide.sys
2011/06/05 14:05:56.0668 5588 volmgr (2b7e885ed951519a12c450d24535dfca) C:\Windows\system32\drivers\volmgr.sys
2011/06/05 14:05:56.0746 5588 volmgrx (cec5ac15277d75d9e5dec2e1c6eaf877) C:\Windows\system32\drivers\volmgrx.sys
2011/06/05 14:05:56.0855 5588 volsnap (5280aada24ab36b01a84a6424c475c8d) C:\Windows\system32\drivers\volsnap.sys
2011/06/05 14:05:56.0917 5588 vsmraid (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys
2011/06/05 14:05:56.0964 5588 WacomPen (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys
2011/06/05 14:05:57.0011 5588 Wanarp (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
2011/06/05 14:05:57.0027 5588 Wanarpv6 (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
2011/06/05 14:05:57.0073 5588 Wd (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys
2011/06/05 14:05:57.0120 5588 Wdf01000 (d02e7e4567da1e7582fbf6a91144b0df) C:\Windows\system32\drivers\Wdf01000.sys
2011/06/05 14:05:57.0229 5588 WimFltr (b14ef15bd757fa488f9c970eee9c0d35) C:\Windows\system32\DRIVERS\wimfltr.sys
2011/06/05 14:05:57.0292 5588 winachsf (9e6c63f94d2c3d884a8936e448b1028b) C:\Windows\system32\DRIVERS\CAX_CNXT.sys
2011/06/05 14:05:57.0401 5588 WmiAcpi (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/06/05 14:05:57.0495 5588 WpdUsb (5e2401b3fc1089c90e081291357371a9) C:\Windows\system32\DRIVERS\wpdusb.sys
2011/06/05 14:05:57.0526 5588 ws2ifsl (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys
2011/06/05 14:05:57.0619 5588 WUDFRd (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/06/05 14:05:57.0666 5588 XAudio (f22e443518bc599d12888daf292a56d8) C:\Windows\system32\DRIVERS\xaudio64.sys
2011/06/05 14:05:57.0760 5588 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
2011/06/05 14:05:57.0775 5588 ================================================== ==============================
2011/06/05 14:05:57.0775 5588 Scan finished
2011/06/05 14:05:57.0775 5588 ================================================== ==============================
2011/06/05 14:05:57.0791 5772 Detected object count: 0
2011/06/05 14:05:57.0791 5772 Actual detected object count: 0
No. This is legit Combofix file. Put it into Avira's exceptions.So should I select the "remove" option from Avira's message on C:\ComboFix\handle.cfxxe?
Which browser is getting redirected?
Download OTL to your Desktop.
- Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- Click the Scan All Users checkbox.
- Under the Custom Scan box paste this in:
netsvcs
drivers32
%SYSTEMDRIVE%\*.*
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\Fonts\*.exe
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lnk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Desktop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
%systemroot%\AppPatch\Custom\*.*
%APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
%PROGRAMFILES%\PC-Doctor\Downloads\*.*
%PROGRAMFILES%\Internet Explorer\*.tmp
%PROGRAMFILES%\Internet Explorer\*.dat
%USERPROFILE%\My Documents\*.exe
%USERPROFILE%\*.exe
%systemroot%\ADDINS\*.*
%systemroot%\assembly\*.bak2
%systemroot%\Config\*.*
%systemroot%\REPAIR\*.bak2
%systemroot%\SECURITY\Database\*.sdb /x
%systemroot%\SYSTEM\*.bak2
%systemroot%\Web\*.bak2
%systemroot%\Driver Cache\*.*
%PROGRAMFILES%\Mozilla Firefox\0*.exe
%ProgramFiles%\Microsoft Common\*.*
%ProgramFiles%\TinyProxy.
%USERPROFILE%\Favorites\*.url /x
%systemroot%\system32\*.bk
%systemroot%\*.te
%systemroot%\system32\system32\*.*
%ALLUSERSPROFILE%\*.dat /x
%systemroot%\system32\drivers\*.rmv
dir /b "%systemroot%\system32\*.exe" | find /i " " /c
dir /b "%systemroot%\*.exe" | find /i " " /c
%PROGRAMFILES%\Microsoft\*.*
%systemroot%\System32\Wbem\proquota.exe
%PROGRAMFILES%\Mozilla Firefox\*.dat
%USERPROFILE%\Cookies\*.txt /x
%SystemRoot%\system32\fonts\*.*
%systemroot%\system32\winlog\*.*
%systemroot%\system32\Language\*.*
%systemroot%\system32\Settings\*.*
%systemroot%\system32\*.quo
%SYSTEMROOT%\AppPatch\*.exe
%SYSTEMROOT%\inf\*.exe
%SYSTEMROOT%\Installer\*.exe
%systemroot%\system32\config\*.bak2
%systemroot%\system32\Computers\*.*
%SystemRoot%\system32\Sound\*.*
%SystemRoot%\system32\SpecialImg\*.*
%SystemRoot%\system32\code\*.*
%SystemRoot%\system32\draft\*.*
%SystemRoot%\system32\MSSSys\*.*
%ProgramFiles%\Javascript\*.*
%systemroot%\pchealth\helpctr\System\*.exe /s
%systemroot%\Web\*.exe
%systemroot%\system32\msn\*.*
%systemroot%\system32\*.tro
%AppData%\Microsoft\Installer\msupdates\*.*
%ProgramFiles%\Messenger\*.*
%systemroot%\system32\systhem32\*.*
%systemroot%\system\*.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
/md5start
/md5stop
- Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
- When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
- Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.